CVE-2006-5090
Phoenix Evolution CMS - '/modules/pageedit/index.php?pageid' Cross-Site Scripting
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
3Exploited in Wild
-Decision
Descriptions
Multiple cross-site scripting (XSS) vulnerabilities in Phoenix Evolution CMS (PECMS) allow remote attackers to inject arbitrary web script or HTML via the (1) mod or (2) action parameters in index.php, or the (3) pageid parameter in modules/pageedit/index.php. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
Múltiples vulnerabilidades de secuencias de comandos en sitios cruzados (XSS) en Phoenix Evolution CMS (PECMS) permite a un atacante remoto inyectar secuencias de comandos web o HTML de sue elección a través de los parámetros (1)mod o (2)action en index.php, o el parámetro (3)pageid en modules/pageedit/index.php. NOTA: el origen de esta información es desconocido; los detalles se obtuvieron de terceras fuentes de información.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2006-09-26 First Exploit
- 2006-09-29 CVE Reserved
- 2006-09-29 CVE Published
- 2024-02-22 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
http://osvdb.org/33676 | Vdb Entry | |
http://osvdb.org/33677 | Vdb Entry |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/28693 | 2006-09-26 | |
https://www.exploit-db.com/exploits/28692 | 2006-09-26 | |
http://www.securityfocus.com/bid/20212 | 2024-08-07 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Phoenix Evolution Search vendor "Phoenix Evolution" | Phoenix Evolution Cms Search vendor "Phoenix Evolution" for product "Phoenix Evolution Cms" | * | - |
Affected
|