MEDIUM
Cross-site scripting (XSS) vulnerability in index.php in Contrexx CMS 1.0.8 and earlier allows remote attackers to inject arbitrary web script or HTML via the query string (PHP_SELF)
Published Mar 19, 2006
4.3
MEDIUMCVSS 2.0
EPSS 1.78%
Description
Cross-site scripting (XSS) vulnerability in index.php in Contrexx CMS 1.0.8 and earlier allows remote attackers to inject arbitrary web script or HTML via the query string (PHP_SELF).
Affected products
No data.
OR
- ≤ 1.0.8
- 1.0.4
- 1.0.5
- 1.0.7
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (0)
No CWE recorded.
References (10)
- http://secunia.com/advisories/19294 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://securityreason.com/securityalert/599 third-party-advisoryx_refsource_SREASON
- http://soot.shabgard.org/Contrexx-CMS.txt x_refsource_MISCExploit
- http://www.contrexx.com/?section=media1&act=download&path=/media/archive1/Opensource/Bugfixes/contrexx_1.0.8/&file=contrexx_v1.0.8_bugfix_27-02-06.zip x_refsource_MISC
- http://www.contrexx.com/?section=news&cmd=details&newsid=54 x_refsource_MISC
- http://www.securityfocus.com/archive/1/428075/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/bid/17128 vdb-entryx_refsource_BIDExploit
- http://www.vupen.com/english/advisories/2006/1013 vdb-entryx_refsource_VUPEN
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2006-1297 Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25332 vdb-entryx_refsource_XF
| Link | Providers | Tags |
|---|---|---|
| http://secunia.com/advisories/19294 | third-party-advisoryx_refsource_SECUNIAVendor Advisory | |
| http://securityreason.com/securityalert/599 | third-party-advisoryx_refsource_SREASON | |
| http://soot.shabgard.org/Contrexx-CMS.txt | x_refsource_MISCExploit | |
| http://www.contrexx.com/?section=media1&act=download&path=/media/archive1/Opensource/Bugfixes/contrexx_1.0.8/&file=contrexx_v1.0.8_bugfix_27-02-06.zip | x_refsource_MISC | |
| http://www.contrexx.com/?section=news&cmd=details&newsid=54 | x_refsource_MISC | |
| http://www.securityfocus.com/archive/1/428075/100/0/threaded | mailing-listx_refsource_BUGTRAQ | |
| http://www.securityfocus.com/bid/17128 | vdb-entryx_refsource_BIDExploit | |
| http://www.vupen.com/english/advisories/2006/1013 | vdb-entryx_refsource_VUPEN | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2006-1297 | Advisory | |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/25332 | vdb-entryx_refsource_XF |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Mar 19, 2006
Updated Aug 7, 2024
Reserved Mar 19, 2006
Link CVE-2006-1293
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2006-1297 Assigner mitre
Published Mar 19, 2006
Updated Aug 7, 2024
Exploited since n/a
Link EUVD-2006-1297