Lucene search

K
cveMitreCVE-2006-5130
HistoryOct 03, 2006 - 4:03 a.m.

CVE-2006-5130

2006-10-0304:03:00
mitre
web.nvd.nist.gov
22
cve-2006-5130
cross-site scripting
xss
security vulnerability
ph03y3nk jaf cms

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

5.9

Confidence

High

EPSS

0.004

Percentile

73.3%

Multiple cross-site scripting (XSS) vulnerabilities in ph03y3nk just another flat file (JAF) CMS 4.0 RC1 allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) url, (3) title, and (4) about parameters in a forum post. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

Affected configurations

Nvd
Node
salims_softhousejaf_cmsMatch4.0rc1
VendorProductVersionCPE
salims_softhousejaf_cms4.0cpe:2.3:a:salims_softhouse:jaf_cms:4.0:rc1:*:*:*:*:*:*

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

5.9

Confidence

High

EPSS

0.004

Percentile

73.3%

Related for CVE-2006-5130