CVE-2006-4794
e107 website system 0.7.5 - 'admin.php?Query String (PATH_INFO)' Cross-Site Scripting
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
11Exploited in Wild
-Decision
Descriptions
Multiple cross-site scripting (XSS) vulnerabilities in e107 0.7.5 allow remote attackers to inject arbitrary web script or HTML via the query string (PATH_INFO) in (1) contact.php, (2) download.php, (3) admin.php, (4) fpw.php, (5) news.php, (6) search.php, (7) signup.php, (8) submitnews.php, and (9) user.php. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
Múltiples vulnerabilidades de secuencias de comandos en sitios cruzados (XSS) permiten a atacantes remotos inyectar secuencias de comandos web o HTML de su elección mediante la cadena de consulta (PATH_INFO) en (1) contact.php, (2) download.php, (3) admin.php, (4) fpw.php, (5) news.php, (6) search.php, (7) signup.php, (8) submitnews.php, y (9) user.php. NOTA: la procedencia de esta información es desconocida; los detalles se han obtenido de información de terceros.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2006-09-13 First Exploit
- 2006-09-14 CVE Reserved
- 2006-09-14 CVE Published
- 2024-08-04 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
CAPEC
References (20)
URL | Tag | Source |
---|---|---|
http://www.osvdb.org/30979 | Vdb Entry | |
http://www.osvdb.org/30980 | Vdb Entry | |
http://www.osvdb.org/30981 | Vdb Entry | |
http://www.osvdb.org/30982 | Vdb Entry | |
http://www.osvdb.org/30983 | Vdb Entry | |
http://www.osvdb.org/30984 | Vdb Entry | |
http://www.osvdb.org/30985 | Vdb Entry | |
http://www.osvdb.org/30986 | Vdb Entry | |
http://www.osvdb.org/30987 | Vdb Entry |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/28547 | 2006-09-13 | |
https://www.exploit-db.com/exploits/28545 | 2006-09-13 | |
https://www.exploit-db.com/exploits/28546 | 2006-09-13 | |
https://www.exploit-db.com/exploits/28548 | 2006-09-13 | |
https://www.exploit-db.com/exploits/28549 | 2006-09-13 | |
https://www.exploit-db.com/exploits/28552 | 2006-09-13 | |
https://www.exploit-db.com/exploits/28551 | 2006-09-13 | |
https://www.exploit-db.com/exploits/28554 | 2006-09-13 | |
https://www.exploit-db.com/exploits/28556 | 2006-09-13 | |
http://www.securityfocus.com/bid/19997 | 2024-08-07 | |
http://www.securityfocus.com/data/vulnerabilities/exploits/19997.html | 2024-08-07 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|