Cross-site scripting (XSS) vulnerability in search.html in Alkacon OpenCms 6.0.0, 6.0.2, and 6.0.3 allows remote attackers to inject arbitrary web script or HTML via the query parameter in a search action.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 00:11
Type | Values Removed | Values Added |
---|---|---|
References | () http://secunia.com/advisories/20251 - Patch, Vendor Advisory | |
References | () http://securitytracker.com/id?1016158 - | |
References | () http://www.eazel.es/media/advisory002-OpenCms-Xml-Content-Demo-search-engine-Cross-site-scripting.html - Exploit | |
References | () http://www.osvdb.org/25710 - | |
References | () http://www.securityfocus.com/archive/1/434932/100/0/threaded - | |
References | () http://www.vupen.com/english/advisories/2006/1931 - |
Information
Published : 2006-05-24 23:02
Updated : 2024-11-21 00:11
NVD link : CVE-2006-2571
Mitre link : CVE-2006-2571
CVE.ORG link : CVE-2006-2571
JSON object : View
Products Affected
alkacon
- opencms
CWE