CVE-2006-6420
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Multiple cross-site scripting (XSS) vulnerabilities in jce.php in the JCE Admin Component in Ryan Demmer Joomla Content Editor (JCE) 1.1.0 beta 2 and earlier for Joomla! (com_jce) allow remote attackers to inject arbitrary web script or HTML via the (1) img, (2) title, (3) w, or (4) h parameter, different vectors than CVE-2006-6166. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.
Múltiples vulnerabildades de secuencias de comandos en sitios cruzandos (XSS) en jce.php en JCE Admin Component en Ryan Demmer Joomla Content Editor (JCE) 1.1.0 beta 2 y anteriores para Joomla! (com_jce) permite a un atacante remoto inyectar secuencias de comandos web o HTML a través de los parámetros (1) img, (2) title, (3) w, o (4) h, vectores diferentes que CVE-2006-6166. NOTA: la procedencia de esta información es desconocida; los detalles han sido obtenidos a partir de la información de terceros.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2006-12-09 CVE Reserved
- 2006-12-10 CVE Published
- 2024-05-04 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/21496 | Vdb Entry | |
http://www.vupen.com/english/advisories/2006/4903 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/30799 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/23160 | 2017-07-29 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Ryan Demmer Search vendor "Ryan Demmer" | Joomla Content Editor Search vendor "Ryan Demmer" for product "Joomla Content Editor" | 1.0.4 Search vendor "Ryan Demmer" for product "Joomla Content Editor" and version "1.0.4" | - |
Affected
| ||||||
Ryan Demmer Search vendor "Ryan Demmer" | Joomla Content Editor Search vendor "Ryan Demmer" for product "Joomla Content Editor" | 1.1.0_beta2 Search vendor "Ryan Demmer" for product "Joomla Content Editor" and version "1.1.0_beta2" | - |
Affected
|