MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in phpMyDirectory 10.4.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) PIC parameter in offers-pix.php, (2) from parameter in cp/index.php, and (3) action parameter in cp/admin_index.php
Published Jun 22, 2006
4.3
MEDIUMCVSS 2.0
EPSS 2.09%
Description
Multiple cross-site scripting (XSS) vulnerabilities in phpMyDirectory 10.4.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) PIC parameter in offers-pix.php, (2) from parameter in cp/index.php, and (3) action parameter in cp/admin_index.php.
Affected products
No data.
OR
- ≤ 10.4.5
- 1.0
- 1.0.1
- 1.0.2
- 1.0.3
- 1.0.4
- 1.0.5
- 1.0.6
- 1.0.7
- 1.0.8
- 1.0.9
- 1.1.0
- 1.1.1
- 1.1.2
- 1.1.3
- 1.1.4
- 1.1.5
- 1.1.6
- 1.1.7
- 1.1.8
- 1.1.9
- 1.2.0
- 1.2.0
- 1.2.1
- 1.3.0
- 1.3.0
- 1.3.1
- 1.3.2
- 1.3.3
- 1.3.4
- 1.3.5
- 1.4.0
- 1.4.1
- 10.1.3
- 10.4.4
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (9)
- http://pridels0.blogspot.com/2006/06/phpmydirectory-xss-vuln.html x_refsource_MISC
- http://secunia.com/advisories/20718 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://www.osvdb.org/26669 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/26670 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/26671 vdb-entryx_refsource_OSVDB
- http://www.securityfocus.com/bid/18539 vdb-entryx_refsource_BID
- http://www.vupen.com/english/advisories/2006/2427 vdb-entryx_refsource_VUPEN
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2006-3135 Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27211 vdb-entryx_refsource_XF
| Link | Providers | Tags |
|---|---|---|
| http://pridels0.blogspot.com/2006/06/phpmydirectory-xss-vuln.html | x_refsource_MISC | |
| http://secunia.com/advisories/20718 | third-party-advisoryx_refsource_SECUNIAVendor Advisory | |
| http://www.osvdb.org/26669 | vdb-entryx_refsource_OSVDB | |
| http://www.osvdb.org/26670 | vdb-entryx_refsource_OSVDB | |
| http://www.osvdb.org/26671 | vdb-entryx_refsource_OSVDB | |
| http://www.securityfocus.com/bid/18539 | vdb-entryx_refsource_BID | |
| http://www.vupen.com/english/advisories/2006/2427 | vdb-entryx_refsource_VUPEN | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2006-3135 | Advisory | |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/27211 | vdb-entryx_refsource_XF |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jun 22, 2006
Updated Aug 7, 2024
Reserved Jun 22, 2006
Link CVE-2006-3138
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2006-3135 Assigner mitre
Published Jun 22, 2006
Updated Aug 7, 2024
Exploited since n/a
Link EUVD-2006-3135