VulnerabilityModified
CVE-2006-3051
Cross-site scripting (XSS) vulnerability in list.php in SixCMS 6.0, and other versions before 6.0.6patch2, allows remote attackers to inject arbitrary script code or HTML via the page parameter.
MEDIUM 5.1EPSS 2.85%
Does this matter?
Lower severity and a low EPSS score (2.85%). Track it; it rarely justifies an emergency change on its own.
Description
Cross-site scripting (XSS) vulnerability in list.php in SixCMS 6.0, and other versions before 6.0.6patch2, allows remote attackers to inject arbitrary script code or HTML via the page parameter.
- CVSS 2.0
- 5.1 MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:P
- EPSS
- 2.85% probability · 86th percentile
- CISA KEV
- Not listed
- Affected
- six offene systeme gmbh/sixcms
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/20655Vendor Advisory
- http://securityreason.com/securityalert/1101
- http://securitytracker.com/id?1016282Exploit
- http://www.majorsecurity.de/advisory/major_rls17.txtExploit, Vendor Advisory
- http://www.securityfocus.com/archive/1/437047/100/0/threaded
- http://www.securityfocus.com/archive/1/437639/100/0/threaded
- http://www.securityfocus.com/bid/18393Exploit
- http://www.vupen.com/english/advisories/2006/2386
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27108
- http://secunia.com/advisories/20655Vendor Advisory
- http://securityreason.com/securityalert/1101
- http://securitytracker.com/id?1016282Exploit
- http://www.majorsecurity.de/advisory/major_rls17.txtExploit, Vendor Advisory
- http://www.securityfocus.com/archive/1/437047/100/0/threaded
- http://www.securityfocus.com/archive/1/437639/100/0/threaded
- http://www.securityfocus.com/bid/18393Exploit
- http://www.vupen.com/english/advisories/2006/2386
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27108
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.