Lucene search

K
cveMitreCVE-2006-3661
HistoryJul 18, 2006 - 3:47 p.m.

CVE-2006-3661

2006-07-1815:47:00
mitre
web.nvd.nist.gov
26
cve-2006-3661
index.php
cutenews
xss vulnerability
remote attackers
web script
html
third party information
nvd

CVSS2

2.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:H/Au:N/C:N/I:P/A:N

AI Score

5.8

Confidence

High

EPSS

0.002

Percentile

54.2%

Cross-site scripting (XSS) vulnerability in Index.PHP in CuteNews 1.4.5 allows remote attackers to inject arbitrary web script or HTML via unknown vectors. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

Affected configurations

Nvd
Node
cutephpcutenewsMatch1.4.5
VendorProductVersionCPE
cutephpcutenews1.4.5cpe:2.3:a:cutephp:cutenews:1.4.5:*:*:*:*:*:*:*

CVSS2

2.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:H/Au:N/C:N/I:P/A:N

AI Score

5.8

Confidence

High

EPSS

0.002

Percentile

54.2%

Related for CVE-2006-3661