Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2006-2975

Опубликовано: 12 июн. 2006
Источник: nvd
CVSS2: 2.6
EPSS Низкий

Описание

Multiple cross-site scripting (XSS) vulnerabilities in pblguestbook.php in PBL Guestbook 1.31 allow remote attackers to inject arbitrary web script or HTML via javascript in the SRC attribute of IMG tags in the (1) name, (2) email, and (3) website parameter, which bypasses XSS protection mechanisms that check for SCRIPT tags but not IMG. NOTE: portions of this description's details are obtained from third party information.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:pbl_guestbook:pbl_guestbook:1.31:*:*:*:*:*:*:*

EPSS

Процентиль: 71%
0.00683
Низкий

2.6 Low

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

github
почти 4 года назад

Multiple cross-site scripting (XSS) vulnerabilities in pblguestbook.php in PBL Guestbook 1.31 allow remote attackers to inject arbitrary web script or HTML via javascript in the SRC attribute of IMG tags in the (1) name, (2) email, and (3) website parameter, which bypasses XSS protection mechanisms that check for SCRIPT tags but not IMG. NOTE: portions of this description's details are obtained from third party information.

EPSS

Процентиль: 71%
0.00683
Низкий

2.6 Low

CVSS2

Дефекты

NVD-CWE-Other