CVE-2006-1479
Multiple cross-site scripting (XSS) vulnerabilities in Serge Rey gtd-php (aka Getting Things Done) 0.5 allow remote attackers to inject arbitrary web script or HTML via the Description field in (1) newProject.php, (2) newList.php, and (3)…
Does this matter?
Lower severity and a low EPSS score (2.95%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple cross-site scripting (XSS) vulnerabilities in Serge Rey gtd-php (aka Getting Things Done) 0.5 allow remote attackers to inject arbitrary web script or HTML via the Description field in (1) newProject.php, (2) newList.php, and (3) newWaitingOn.php; the Title field in (4) newProject.php, (5) newList.php, (6) newWaitingOn.php, (7) newChecklist.php, (8) newContext.php, and (9) newGoal.php; the (10) Category Name field in newCategory.php; the (11) listTitle field in listReport.php; the (12) projectName field in projectReport.php; and the (13) checklistTitle field in checklistReport.php.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 2.95% probability · 86th percentile
- CISA KEV
- Not listed
- Affected
- serge rey/gtd-php
- Source
- cve@mitre.org
References
- http://osvdb.org/ref/24/24149-gtd-php.txtExploit
- http://secunia.com/advisories/19512
- http://www.osvdb.org/24149Exploit
- http://www.osvdb.org/24150Exploit
- http://www.osvdb.org/24151Exploit
- http://www.osvdb.org/24152Exploit
- http://www.osvdb.org/24153Exploit
- http://www.osvdb.org/24154Exploit
- http://www.osvdb.org/24155Exploit
- http://www.osvdb.org/24156Exploit
- http://www.osvdb.org/24157Exploit
- http://www.osvdb.org/24158Exploit
- http://www.securityfocus.com/bid/17366
- http://www.vupen.com/english/advisories/2006/1203
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25553
- http://osvdb.org/ref/24/24149-gtd-php.txtExploit
- http://secunia.com/advisories/19512
- http://www.osvdb.org/24149Exploit
- http://www.osvdb.org/24150Exploit
- http://www.osvdb.org/24151Exploit
- http://www.osvdb.org/24152Exploit
- http://www.osvdb.org/24153Exploit
- http://www.osvdb.org/24154Exploit
- http://www.osvdb.org/24155Exploit
- http://www.osvdb.org/24156Exploit
- http://www.osvdb.org/24157Exploit
- http://www.osvdb.org/24158Exploit
- http://www.securityfocus.com/bid/17366
- http://www.vupen.com/english/advisories/2006/1203
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25553
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.