Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2006-1854

Опубликовано: 19 апр. 2006
Источник: nvd
CVSS2: 2.6
EPSS Низкий

Описание

Multiple cross-site scripting (XSS) vulnerabilities in BluePay Manager 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML during a login action via the (1) Account Name and (2) Username field. NOTE: the vendor has disputed this vulnerability, saying that "it does not exist currently in the Bluepay 2.0 product," and older versions might not have been affected either. As of 20060512, CVE has not formally investigated this dispute

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:bluepay:bluepay_manager:*:*:*:*:*:*:*:*
Версия до 2.0 (включая)

EPSS

Процентиль: 58%
0.00362
Низкий

2.6 Low

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

github
почти 4 года назад

** DISPUTED ** Multiple cross-site scripting (XSS) vulnerabilities in BluePay Manager 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML during a login action via the (1) Account Name and (2) Username field. NOTE: the vendor has disputed this vulnerability, saying that "it does not exist currently in the Bluepay 2.0 product," and older versions might not have been affected either. As of 20060512, CVE has not formally investigated this dispute.

EPSS

Процентиль: 58%
0.00362
Низкий

2.6 Low

CVSS2

Дефекты

NVD-CWE-Other