Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2006-2028

Overview

Vulnerability Score 5.8 5.8
CVE Id CVE-2006-2028
Last Modified 07 Mar 2011 09:34:49
Published 25 Apr 2006 08:06:00
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact PARTIAL PARTIAL
Availability Impact NONE NONE
Access Vector NETWORK
Access Complexity MEDIUM
Authentication NONE

CVE-2006-2028

Summary

Cross-site scripting (XSS) vulnerability in imagelist.php in Jeremy Ashcraft Simplog 0.9.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the imagedir parameter. NOTE: this issue might be resultant from directory traversal.

Vulnerable Systems

Application

  • Simplog 0.9.3


References

VUPEN - ADV-2006-1493

BID - 17653

BUGTRAQ - 20060421 Advisory: Simplog <= 0.93 Multiple Remote Vulnerabilities.

OSVDB - 24880

MISC - http://www.nukedx.com/?getxpl=25

SECUNIA - 19764

FULLDISC - 20060423 RE: Advisory: Simplog <= 0.93 Multiple Remote Vulnerabilities.

XF - simplog-imagelist-xss(25984)

SREASON - 799


Last Updated: 27 May 2016 10:42:18