VulnerabilityModified
CVE-2006-6166
Cross-site scripting (XSS) vulnerability in jce.php in the JCE Admin Component in Ryan Demmer Joomla Content Editor (JCE) 1.0.4 for Joomla!
MEDIUM 6.8EPSS 1.24%
Does this matter?
Lower severity and a low EPSS score (1.24%). Track it; it rarely justifies an emergency change on its own.
Description
Cross-site scripting (XSS) vulnerability in jce.php in the JCE Admin Component in Ryan Demmer Joomla Content Editor (JCE) 1.0.4 for Joomla! (com_jce), without the 20060821 jce_patch, allows remote attackers to inject arbitrary web script or HTML via the mosConfig_live_site parameter.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 1.24% probability · 67th percentile
- CISA KEV
- Not listed
- Affected
- ryan demmer/joomla content editor
- Source
- cve@mitre.org
References
- http://forum.joomla.org/index.php?topic=113796.new#newPatch
- http://www.cellardoor.za.net/index.php?option=com_content&task=view&id=28Patch
- http://www.cellardoor.za.net/index.php?option=com_docman&task=doc_download&gid=51&Itemid=6Patch
- http://forum.joomla.org/index.php?topic=113796.new#newPatch
- http://www.cellardoor.za.net/index.php?option=com_content&task=view&id=28Patch
- http://www.cellardoor.za.net/index.php?option=com_docman&task=doc_download&gid=51&Itemid=6Patch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.