Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2006-3366

Overview

Vulnerability Score 2.6 2.6
CVE Id CVE-2006-3366
Last Modified 07 Mar 2011 09:38:28
Published 06 Jul 2006 04:05:00
Confidentiality Impact NONE NONE
Integrity Impact PARTIAL PARTIAL
Availability Impact NONE NONE
Access Vector NETWORK
Access Complexity HIGH
Authentication NONE

CVE-2006-3366

Summary

Multiple cross-site scripting (XSS) vulnerabilities in V3 Chat allow remote attackers to inject arbitrary web script or HTML via crafted HTML tags, as demonstrated by the IMG tag, in the (1) id parameter in (a) mail/index.php and (b) mail/reply.php; (2) login_id parameter in (c) members/is_online.php; (3) site_id parameter in (d) messenger/online.php, (e) messenger/search.php, and (f) messenger/profile.php; (4) contact_name parameter in messenger/search.php; (5) membername parameter in (g) messenger/profileview.php; (6) unspecified parameters used when "editing a profile"; and (7) cust_name parameter in (h) messenger/expire.php. NOTE: The vendor disputes the vectors involving files in the messenger directory, stating "... the referenced folder 'messenger' was never available to the general public...".

Vulnerable Systems

Application

  • V3 Chat Beta


References

VUPEN - ADV-2006-2474

BUGTRAQ - 20060622 Re: V3Chat Instant Messenger - XSS

BUGTRAQ - 20060617 V3Chat Instant Messenger - XSS

SECTRACK - 1016340

BID - 18543


Last Updated: 27 May 2016 10:42:58