CVE-2006-5127
Multiple cross-site scripting (XSS) vulnerabilities in Bartels Schoene ConPresso before 4.0.5a allow remote attackers to inject arbitrary web script or HTML via (1) the nr parameter in detail.php, (2) the msg parameter in db_mysql.inc.php, and (3) the…
Does this matter?
Lower severity and a low EPSS score (1.66%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple cross-site scripting (XSS) vulnerabilities in Bartels Schoene ConPresso before 4.0.5a allow remote attackers to inject arbitrary web script or HTML via (1) the nr parameter in detail.php, (2) the msg parameter in db_mysql.inc.php, and (3) the pos parameter in index.php.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 1.66% probability · 75th percentile
- CISA KEV
- Not listed
- Affected
- conpresso/conpresso cms
- Source
- cve@mitre.org
References
- http://download.compresso.de/compresso-4.0.5a.zipPatch
- http://secunia.com/advisories/22145
- http://securityreason.com/securityalert/1671
- http://www.majorsecurity.de/index_2.php?major_rls=major_rls28Exploit
- http://www.securityfocus.com/archive/1/447358/100/0/threaded
- http://www.securityfocus.com/bid/20273Exploit, Patch
- http://www.vupen.com/english/advisories/2006/3868
- https://exchange.xforce.ibmcloud.com/vulnerabilities/29272
- http://download.compresso.de/compresso-4.0.5a.zipPatch
- http://secunia.com/advisories/22145
- http://securityreason.com/securityalert/1671
- http://www.majorsecurity.de/index_2.php?major_rls=major_rls28Exploit
- http://www.securityfocus.com/archive/1/447358/100/0/threaded
- http://www.securityfocus.com/bid/20273Exploit, Patch
- http://www.vupen.com/english/advisories/2006/3868
- https://exchange.xforce.ibmcloud.com/vulnerabilities/29272
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.