VulnerabilityModified
CVE-2006-2821
Multiple cross-site scripting (XSS) vulnerabilities in DeltaScripts Pro Publish allow remote attackers to inject arbitrary web script or HTML via the (1) artid parameter in art.php and the (2) catname parameter in cat.php.
MEDIUM 6.8EPSS 1.93%
Does this matter?
Lower severity and a low EPSS score (1.93%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple cross-site scripting (XSS) vulnerabilities in DeltaScripts Pro Publish allow remote attackers to inject arbitrary web script or HTML via the (1) artid parameter in art.php and the (2) catname parameter in cat.php.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 1.93% probability · 79th percentile
- CISA KEV
- Not listed
- Affected
- deltascripts/pro publish
- Source
- cve@mitre.org
References
- http://securityreason.com/securityalert/1027
- http://soot.shabgard.org/bugs/propublish.txtExploit
- http://www.securityfocus.com/archive/1/435787/100/0/threaded
- http://www.securityfocus.com/bid/18243Exploit
- http://securityreason.com/securityalert/1027
- http://soot.shabgard.org/bugs/propublish.txtExploit
- http://www.securityfocus.com/archive/1/435787/100/0/threaded
- http://www.securityfocus.com/bid/18243Exploit
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.