Lucene search

K
cve[email protected]CVE-2006-3257
HistoryJun 28, 2006 - 1:45 a.m.

CVE-2006-3257

2006-06-2801:45:00
web.nvd.nist.gov
21
cve-2006-3257
xss
claroline 1.7.7
security vulnerabilities
remote attack

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

6 Medium

AI Score

Confidence

High

0.004 Low

EPSS

Percentile

74.7%

Multiple cross-site scripting (XSS) vulnerabilities in Claroline 1.7.7 allow remote attackers to inject arbitrary HTML or web script via unspecified attack vectors, possibly including (1) calendar/myagenda.php, (2) document/document.php, (3) phpbb/newtopic.php, (4) tracking/userLog.php, and (5) wiki/page.php.

Affected configurations

NVD
Node
clarolineclarolineMatch1.7.7
CPENameOperatorVersion
claroline:clarolineclarolineeq1.7.7

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

6 Medium

AI Score

Confidence

High

0.004 Low

EPSS

Percentile

74.7%

Related for CVE-2006-3257