VulnerabilityModified
CVE-2006-2515
Cross-site scripting (XSS) vulnerability in index.php in Hiox Guestbook 3.1 allows remote attackers to inject arbitrary web script or HTML via the input forms for signing the guestbook.
MEDIUM 6.8EPSS 1.44%
Does this matter?
Lower severity and a low EPSS score (1.44%). Track it; it rarely justifies an emergency change on its own.
Description
Cross-site scripting (XSS) vulnerability in index.php in Hiox Guestbook 3.1 allows remote attackers to inject arbitrary web script or HTML via the input forms for signing the guestbook.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 1.44% probability · 72th percentile
- CISA KEV
- Not listed
- Affected
- hiox india/guest book
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/20252
- http://securityreason.com/securityalert/938
- http://www.osvdb.org/25712
- http://www.securityfocus.com/archive/1/434686/100/0/threaded
- http://www.vupen.com/english/advisories/2006/1929
- https://exchange.xforce.ibmcloud.com/vulnerabilities/26620
- http://secunia.com/advisories/20252
- http://securityreason.com/securityalert/938
- http://www.osvdb.org/25712
- http://www.securityfocus.com/archive/1/434686/100/0/threaded
- http://www.vupen.com/english/advisories/2006/1929
- https://exchange.xforce.ibmcloud.com/vulnerabilities/26620
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.