Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2006-3089

Overview

Vulnerability Score 4.3 4.3
CVE Id CVE-2006-3089
Last Modified 05 Sep 2008 05:06:13
Published 19 Jun 2006 05:02:00
Confidentiality Impact NONE NONE
Integrity Impact PARTIAL PARTIAL
Availability Impact NONE NONE
Access Vector NETWORK
Access Complexity MEDIUM
Authentication NONE

CVE-2006-3089

Summary

Multiple cross-site scripting (XSS) vulnerabilities in PhpMyFactures 1.0, and possibly 1.2 and earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) prefixe_dossier parameter in (a) /inc/header.php; (2) msg parameter in (b) /remises/ajouter_remise.php, (c) /tva/ajouter_tva.php, (d) /stocks/ajouter.php, (e) /pays/ajouter_pays.php, (f) /produits/ajouter_cat.php, (g) /produits/ajouter_produit.php and (h) /produits/modifier_cat.php; (3) tire parameter in /remises/ajouter_remise.php; (4) quantite, (5) taux and (6) date parameter in /stocks/ajouter.php; and (7) pays and (8) prefixe parameter in /pays/ajouter_pays.php.

Vulnerable Systems

Application

  • Phpmyfactures 1.0

  • Phpmyfactures 1.2


References

XF - phpmyfactures-multiple-scripts-xss(27208)

BUGTRAQ - 20060610 PhpMyFactures 1.0 Cross Site Scripting, SQL Injection, Full Path Disclosure and others

OSVDB - 26485

OSVDB - 26484

OSVDB - 26483

OSVDB - 26482

OSVDB - 26481

OSVDB - 26480

OSVDB - 26479

OSVDB - 26478

MISC - http://www.acid-root.new.fr/advisories/phpmyfactures.txt

SECUNIA - 20642

SREASON - 1111


Last Updated: 27 May 2016 10:42:52