CVE-2006-7050

Cross-site scripting (XSS) vulnerability in WikkaWiki (Wikka Wiki) before 1.1.6.2 allows remote attackers to inject arbitrary javascript via (1) events in forced links (url parameter) that are not properly handled in formatters/wakka.php, and possibly (2) other vectors in wikka.php.
Configurations

Configuration 1 (hide)

cpe:2.3:a:wikkawiki:wikkawiki:*:*:*:*:*:*:*:*

History

21 Nov 2024, 00:24

Type Values Removed Values Added
References () http://secunia.com/advisories/20628 - Patch () http://secunia.com/advisories/20628 - Patch
References () http://wikkawiki.org/WikkaReleaseNotes - () http://wikkawiki.org/WikkaReleaseNotes -
References () http://wush.net/trac/wikka/changeset/47 - () http://wush.net/trac/wikka/changeset/47 -
References () http://wush.net/trac/wikka/ticket/142 - () http://wush.net/trac/wikka/ticket/142 -
References () http://www.securityfocus.com/bid/18481 - () http://www.securityfocus.com/bid/18481 -
References () http://www.vupen.com/english/advisories/2006/2381 - () http://www.vupen.com/english/advisories/2006/2381 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/27227 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/27227 -

Information

Published : 2007-02-24 00:28

Updated : 2024-11-21 00:24


NVD link : CVE-2006-7050

Mitre link : CVE-2006-7050

CVE.ORG link : CVE-2006-7050


JSON object : View

Products Affected

wikkawiki

  • wikkawiki