CVE-2006-7078
Multiple cross-site scripting (XSS) vulnerabilities in Professional Home Page Tools Login Script, as of July 2006, allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) vorname, and (3) nachname parameters in the register…
Does this matter?
Lower severity and a low EPSS score (1.22%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple cross-site scripting (XSS) vulnerabilities in Professional Home Page Tools Login Script, as of July 2006, allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) vorname, and (3) nachname parameters in the register script. NOTE: some details have been obtained from third party sources.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 1.22% probability · 67th percentile
- CISA KEV
- Not listed
- Affected
- professional home page tools login script/professional home page tools login script
- Source
- cve@mitre.org
References
- http://lists.grok.org.uk/pipermail/full-disclosure/2006-July/048194.html
- http://secunia.com/advisories/21206Vendor Advisory
- http://securityreason.com/securityalert/2329
- http://www.securityfocus.com/archive/1/441194/100/0/threaded
- http://www.vupen.com/english/advisories/2006/2981
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27967
- http://lists.grok.org.uk/pipermail/full-disclosure/2006-July/048194.html
- http://secunia.com/advisories/21206Vendor Advisory
- http://securityreason.com/securityalert/2329
- http://www.securityfocus.com/archive/1/441194/100/0/threaded
- http://www.vupen.com/english/advisories/2006/2981
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27967
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.