CVE-2006-3607
SoftBiz Banner Exchange Script 1.0 - 'gen_confirm_mem.php?PHPSESSID' Cross-Site Scripting
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
6Exploited in Wild
-Decision
Descriptions
Multiple cross-site scripting (XSS) vulnerabilities in Softbiz Banner Exchange Script (aka Banner Exchange Network Script) 1.0 allow remote attackers to inject arbitrary web script or HTML via (1) the city parameter in (a) insertmember.php, and (2) a PHPSESSID cookie in (b) lostpassword.php, (c) gen_confirm_mem.php, and (d) index.php.
Múltiples vulnerabilidades de secuencias de comandos en sitios cruzados (XSS) en Softbiz Banner Exchange Script (también conocido como Banner Exchange Network Script) 1.0 permiten a atacantes remotos inyectar secuencias de comandos web o HTML de su elección a través de el parámetro (1) city de (a) insertmember.php, y (2) una cookie PHPSESSID en (b) lostpassword.php, (c) gen_configm_mem.php, y (d) index.php.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2006-06-29 First Exploit
- 2006-07-14 CVE Reserved
- 2006-07-14 CVE Published
- 2023-05-18 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
CAPEC
References (9)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/archive/1/438705/100/200/threaded | Mailing List | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/27460 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/27461 | Vdb Entry |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/28139 | 2006-06-29 | |
https://www.exploit-db.com/exploits/28140 | 2006-06-29 | |
https://www.exploit-db.com/exploits/28137 | 2006-06-29 | |
https://www.exploit-db.com/exploits/28138 | 2006-06-29 | |
http://ellsec.org/print.php?type=N&item_id=141 | 2024-08-07 | |
http://www.securityfocus.com/bid/18735 | 2024-08-07 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Softbiz Search vendor "Softbiz" | Banner Exchange Search vendor "Softbiz" for product "Banner Exchange" | 1.0 Search vendor "Softbiz" for product "Banner Exchange" and version "1.0" | - |
Affected
|