VulnerabilityModified
CVE-2006-0507
Multiple cross-site scripting (XSS) vulnerabilities in Easy CMS allow remote attackers to inject arbitrary web script or HTML via (1) unknown attack vectors in the administrative interface and (2) input fields of the contact form.
MEDIUM 4.3EPSS 1.34%
Does this matter?
Lower severity and a low EPSS score (1.34%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple cross-site scripting (XSS) vulnerabilities in Easy CMS allow remote attackers to inject arbitrary web script or HTML via (1) unknown attack vectors in the administrative interface and (2) input fields of the contact form.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 1.34% probability · 70th percentile
- CISA KEV
- Not listed
- Affected
- easy cms/easy cms
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/18673Vendor Advisory
- http://www.securityfocus.com/archive/1/423442/100/0/threaded
- http://www.securityfocus.com/archive/1/423563/100/0/threaded
- http://www.securityfocus.com/archive/1/424431/100/0/threaded
- http://www.securityfocus.com/bid/16430
- http://www.vupen.com/english/advisories/2006/0385
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24371
- http://secunia.com/advisories/18673Vendor Advisory
- http://www.securityfocus.com/archive/1/423442/100/0/threaded
- http://www.securityfocus.com/archive/1/423563/100/0/threaded
- http://www.securityfocus.com/archive/1/424431/100/0/threaded
- http://www.securityfocus.com/bid/16430
- http://www.vupen.com/english/advisories/2006/0385
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24371
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.