MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in (a) PMOS Help Desk 2.4, formerly (b) InverseFlow Help Desk 2.31 and also sold as (c) Ace Helpdesk 2.31, allow remote attackers to inject arbitrary web script or HTML via the (1) id or email parameter to ticketview.php, or (2) the email parameter to ticket.php
Published Nov 28, 2006
6.8
MEDIUMCVSS 2.0
EPSS 2.86%
Description
Multiple cross-site scripting (XSS) vulnerabilities in (a) PMOS Help Desk 2.4, formerly (b) InverseFlow Help Desk 2.31 and also sold as (c) Ace Helpdesk 2.31, allow remote attackers to inject arbitrary web script or HTML via the (1) id or email parameter to ticketview.php, or (2) the email parameter to ticket.php.
Affected products
No data.
OR
- 2.3.1
- 2.31
- 2.4
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (0)
No CWE recorded.
References (14)
- http://secunia.com/advisories/23052 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/23070 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/23071 third-party-advisoryx_refsource_SECUNIA
- http://securityreason.com/securityalert/1928 third-party-advisoryx_refsource_SREASON
- http://www.attrition.org/pipermail/vim/2006-November/001148.html mailing-listx_refsource_VIM
- http://www.osvdb.org/30667 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/34034 vdb-entryx_refsource_OSVDB
- http://www.securityfocus.com/archive/1/452397/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/bid/21250 vdb-entryx_refsource_BID
- http://www.vupen.com/english/advisories/2006/4670 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2006/4671 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2006/4672 vdb-entryx_refsource_VUPEN
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2006-6141 Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/30489 vdb-entryx_refsource_XF
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Nov 28, 2006
Updated Aug 7, 2024
Reserved Nov 28, 2006
Link CVE-2006-6158
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2006-6141 Assigner mitre
Published Nov 28, 2006
Updated Aug 7, 2024
Exploited since n/a
Link EUVD-2006-6141