Lucene search

K
nvd[email protected]NVD:CVE-2006-5626
HistoryOct 31, 2006 - 8:07 p.m.

CVE-2006-5626

2006-10-3120:07:00
web.nvd.nist.gov
2

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.9

Confidence

High

EPSS

0.012

Percentile

85.0%

Cross-site scripting (XSS) vulnerability in cms_images/js/htmlarea/htmlarea.php in phpFaber Content Management System (CMS) before 1.3.36 on 20061026 allows remote attackers to inject arbitrary web script or HTML, probably via arbitrary parameters in the query string, as demonstrated with a vigilon parameter. NOTE: earlier downloads of 1.3.36 have the vulnerability; the software was updated without changing the version number.

Affected configurations

Nvd
Node
phpfaberphpfaber_content_management_systemRange1.3.36
VendorProductVersionCPE
phpfaberphpfaber_content_management_system*cpe:2.3:a:phpfaber:phpfaber_content_management_system:*:*:*:*:*:*:*:*

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.9

Confidence

High

EPSS

0.012

Percentile

85.0%

Related for NVD:CVE-2006-5626