Lucene search

K
cve[email protected]CVE-2006-7050
HistoryFeb 24, 2007 - 12:28 a.m.

CVE-2006-7050

2007-02-2400:28:00
web.nvd.nist.gov
26
cve-2006-7050
cross-site scripting
xss
wikkawiki
wikka wiki
nvd
security vulnerability

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

6.2 Medium

AI Score

Confidence

High

0.017 Low

EPSS

Percentile

87.7%

Cross-site scripting (XSS) vulnerability in WikkaWiki (Wikka Wiki) before 1.1.6.2 allows remote attackers to inject arbitrary javascript via (1) events in forced links (url parameter) that are not properly handled in formatters/wakka.php, and possibly (2) other vectors in wikka.php.

Affected configurations

NVD
Node
wikkawikiwikkawikiRange1.1.6.1
CPENameOperatorVersion
wikkawiki:wikkawikiwikkawikile1.1.6.1

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

6.2 Medium

AI Score

Confidence

High

0.017 Low

EPSS

Percentile

87.7%

Related for CVE-2006-7050