CVE-2006-5530
Simpnews 2.x - 'index.php' Cross-Site Scripting
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
3Exploited in Wild
-Decision
Descriptions
Multiple cross-site scripting (XSS) vulnerabilities in Boesch SimpNews before 2.34.01 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to (1) admin/index.php, (2) admin/pwlost.php, and unspecified other files. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
Vulnerabilidades de cruce de sitios en scripts (XSS) en Boesch SimpNews versiones anteriores a 2.34.01 permiten a atacantes remotos inyectar scripts WEB o HTML mediante parámetros sin especificar en (1) admin/index.php, (2) admin/pwlost.php, y otros filos sin especificar.
NOTA. El origen de esta información es desconocido; los detalles se han obtenido a partir de información de terceros.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2006-10-24 First Exploit
- 2006-10-26 CVE Reserved
- 2006-10-26 CVE Published
- 2024-03-20 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
http://www.vupen.com/english/advisories/2006/4162 | Vdb Entry |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/28858 | 2006-10-24 | |
https://www.exploit-db.com/exploits/28859 | 2006-10-24 | |
http://www.securityfocus.com/bid/20714 | 2024-08-07 |
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/22535 | 2012-08-06 | |
http://www.boesch-it.de/sw/php-scripts/simpnews/english/index.php | 2012-08-06 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Boesch It-consulting Search vendor "Boesch It-consulting" | Simpnews Search vendor "Boesch It-consulting" for product "Simpnews" | <= 2.34 Search vendor "Boesch It-consulting" for product "Simpnews" and version " <= 2.34" | - |
Affected
| ||||||
Boesch It-consulting Search vendor "Boesch It-consulting" | Simpnews Search vendor "Boesch It-consulting" for product "Simpnews" | 2.0.1 Search vendor "Boesch It-consulting" for product "Simpnews" and version "2.0.1" | - |
Affected
| ||||||
Boesch It-consulting Search vendor "Boesch It-consulting" | Simpnews Search vendor "Boesch It-consulting" for product "Simpnews" | 2.13 Search vendor "Boesch It-consulting" for product "Simpnews" and version "2.13" | - |
Affected
| ||||||
Boesch It-consulting Search vendor "Boesch It-consulting" | Simpnews Search vendor "Boesch It-consulting" for product "Simpnews" | 2.30 Search vendor "Boesch It-consulting" for product "Simpnews" and version "2.30" | - |
Affected
|