Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2006-0860

Overview

Vulnerability Score 4.3 4.3
CVE Id CVE-2006-0860
Last Modified 13 Sep 2011 12:00:00
Published 23 Feb 2006 06:02:00
Confidentiality Impact NONE NONE
Integrity Impact PARTIAL PARTIAL
Availability Impact NONE NONE
Access Vector NETWORK
Access Complexity MEDIUM
Authentication NONE

CVE-2006-0860

Summary

Multiple cross-site scripting (XSS) vulnerabilities in Michael Salzer Guestbox 0.6, and other versions before 0.8, allow remote attackers to inject arbitrary web script or HTML via (1) HTML tags that follow a "http://" string, which bypasses a regular expression check, and (2) other unspecified attack vectors.

Vulnerable Systems

Application

  • Michael Salzer Guestbox 0.6


References

BID - 16751

SECUNIA - 18946

XF - guestbox-gbshow-xss(24798)

VUPEN - ADV-2006-0675

BUGTRAQ - 20060302 Re: Guestbox XSS/an admin bypass

BUGTRAQ - 20060220 Guestbox XSS/an admin bypass

OSVDB - 23375


Last Updated: 27 May 2016 10:41:50