CVE-2006-4739
 
Severity Score
2.6
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Multiple cross-site scripting (XSS) vulnerabilities in Jetbox CMS allow remote attackers to inject arbitrary web script or HTML, as demonstrated via the OriginalImageData parameter to phpthumb.php.
Múltiples vulnerabilidades de secuencias de comandos en sitios cruzados(XSS) en Jetbox CMS permite a un atacante remoto inyectar secuencias de comandos web o HTML de su elección, tal y como se demuestra a través del parámetro OriginalImageData a phpthumb.php.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2006-09-13 CVE Reserved
- 2006-09-13 CVE Published
- 2024-02-06 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
http://securityreason.com/securityalert/1562 | Third Party Advisory | |
http://www.securityfocus.com/archive/1/445652/100/0/threaded | Mailing List | |
http://www.securityfocus.com/bid/19303 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/28842 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Jetbox Search vendor "Jetbox" | Jetbox Cms Search vendor "Jetbox" for product "Jetbox Cms" | 2.1_sr1 Search vendor "Jetbox" for product "Jetbox Cms" and version "2.1_sr1" | - |
Affected
|