// For flags

CVE-2006-6769

 

Severity Score

6.8
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

2
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Multiple cross-site scripting (XSS) vulnerabilities in PHP Live! 3.2.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) search_string parameter in (a) setup/transcripts.php, the (2) l parameter in (b) index.php, the (3) login field in (c) phplive/index.php, and the (4) deptid and (5) x parameters in (d) phplive/message_box.php.

Múltiples vulnerabilidades de secuencias de comandos en sitios cruzados (XSS) en PHP Live! 3.2.2 y anteriores permiten a atacantes remotos inyectar secuencias de comandos web o HTML de su elección a través del parámetro (1) search_string de (a) setup/transcripts.php, el parámetro (2) l de (b) index.php, el campo (3) login en (c) phplive/index.php, y los parámetros (4) deptid y (5) x en (d) phplive/message_box.php.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2006-12-27 CVE Reserved
  • 2006-12-27 CVE Published
  • 2024-08-07 CVE Updated
  • 2024-08-07 First Exploit
  • 2024-09-01 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Php Live
Search vendor "Php Live"
Php Live
Search vendor "Php Live" for product "Php Live"
<= 3.2.2
Search vendor "Php Live" for product "Php Live" and version " <= 3.2.2"
-
Affected
Php Live
Search vendor "Php Live"
Php Live
Search vendor "Php Live" for product "Php Live"
2.8.1
Search vendor "Php Live" for product "Php Live" and version "2.8.1"
-
Affected
Php Live
Search vendor "Php Live"
Php Live
Search vendor "Php Live" for product "Php Live"
3.0
Search vendor "Php Live" for product "Php Live" and version "3.0"
-
Affected