CVE-2006-3958
Multiple unspecified cross-site scripting (XSS) vulnerabilities in Taskjitsu 2.0.3 allow remote attackers to inject arbitrary web script or HTML via (1) the Search Tasks system, or authenticated users via (2) the Edit Task system, (3) the back-end…
Does this matter?
Lower severity and a low EPSS score (1.34%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple unspecified cross-site scripting (XSS) vulnerabilities in Taskjitsu 2.0.3 allow remote attackers to inject arbitrary web script or HTML via (1) the Search Tasks system, or authenticated users via (2) the Edit Task system, (3) the back-end Category Editor system, and (4) "Pages that display task status, email addresses, URL, customer, and project information."
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 1.34% probability · 70th percentile
- CISA KEV
- Not listed
- Affected
- pkr internet/taskjitsu
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/21242Patch, Vendor Advisory
- http://www.osvdb.org/27637
- http://www.pkrinternet.com/download/RELEASE-NOTES.txtURL Repurposed
- http://www.securityfocus.com/bid/19251
- http://www.vupen.com/english/advisories/2006/3058Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/28178
- https://www.pkrinternet.com/taskjitsu/task/3477URL Repurposed
- http://secunia.com/advisories/21242Patch, Vendor Advisory
- http://www.osvdb.org/27637
- http://www.pkrinternet.com/download/RELEASE-NOTES.txtURL Repurposed
- http://www.securityfocus.com/bid/19251
- http://www.vupen.com/english/advisories/2006/3058Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/28178
- https://www.pkrinternet.com/taskjitsu/task/3477URL Repurposed
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.