VulnerabilityModified
CVE-2006-4751
Cross-site scripting (XSS) vulnerability in index.php in Laurentiu Matei eXpandable Home Page (XHP) CMS 0.5.1 allows remote attackers to inject arbitrary web script or HTML via the errcode parameter.
MEDIUM 6.8EPSS 2.16%
Does this matter?
Lower severity and a low EPSS score (2.16%). Track it; it rarely justifies an emergency change on its own.
Description
Cross-site scripting (XSS) vulnerability in index.php in Laurentiu Matei eXpandable Home Page (XHP) CMS 0.5.1 allows remote attackers to inject arbitrary web script or HTML via the errcode parameter.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 2.16% probability · 81th percentile
- CISA KEV
- Not listed
- Affected
- laurentiu matei/expandable home page cms
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/21877Vendor Advisory
- http://securityreason.com/securityalert/1565
- http://securitytracker.com/id?1016823Exploit
- http://www.securityfocus.com/archive/1/445727/100/0/threaded
- http://www.securityfocus.com/bid/19948Exploit
- http://www.vupen.com/english/advisories/2006/3560
- https://exchange.xforce.ibmcloud.com/vulnerabilities/28860
- http://secunia.com/advisories/21877Vendor Advisory
- http://securityreason.com/securityalert/1565
- http://securitytracker.com/id?1016823Exploit
- http://www.securityfocus.com/archive/1/445727/100/0/threaded
- http://www.securityfocus.com/bid/19948Exploit
- http://www.vupen.com/english/advisories/2006/3560
- https://exchange.xforce.ibmcloud.com/vulnerabilities/28860
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.