Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2006-1898

Overview

Vulnerability Score 2.6 2.6
CVE Id CVE-2006-1898
Last Modified 03 Jan 2013 12:00:00
Published 20 Apr 2006 06:02:00
Confidentiality Impact NONE NONE
Integrity Impact PARTIAL PARTIAL
Availability Impact NONE NONE
Access Vector NETWORK
Access Complexity HIGH
Authentication NONE

CVE-2006-1898

Summary

Multiple cross-site scripting (XSS) vulnerabilities in Ralph Capper Tiny PHP Forum (TPF) 3.6 allow remote attackers to inject arbitrary web script or HTML via (1) the uname parameter in a view action in profile.php and (2) a login name. NOTE: the "Access to hash password" issue is already covered by CVE-2006-0103.

Vulnerable Systems

Application

  • Ralph Capper Tinyphpforum 3.6


References

BUGTRAQ - 20060417 Tiny PHP forum - vulns

XF - tinyphpforum-profile-error-xss(25856)

BID - 17553

SREASON - 773

SREASON - 728


Last Updated: 27 May 2016 11:01:32