CVE-2006-1295

Cross-site scripting (XSS) vulnerability in recherche.php3 in SPIP 1.8.2-g allows remote attackers to inject arbitrary web script or HTML via the recherche parameter.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:spip:spip:1.8.2e:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:1.8.2g:*:*:*:*:*:*:*

History

21 Nov 2024, 00:08

Type Values Removed Values Added
References () http://www.securityfocus.com/bid/17130 - () http://www.securityfocus.com/bid/17130 -
References () http://www.silitix.com/spip-xss.html - () http://www.silitix.com/spip-xss.html -
References () http://www.zone-h.fr/advisories/read/id=1105 - () http://www.zone-h.fr/advisories/read/id=1105 -
References () http://zone.spip.org/trac/spip-zone/changeset/1672 - Patch () http://zone.spip.org/trac/spip-zone/changeset/1672 - Patch
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/25389 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/25389 -

Information

Published : 2006-03-19 23:02

Updated : 2024-11-21 00:08


NVD link : CVE-2006-1295

Mitre link : CVE-2006-1295

CVE.ORG link : CVE-2006-1295


JSON object : View

Products Affected

spip

  • spip