Vulnerability Name: | CVE-2006-0208 | ||||||||||||||||
Assigned: | 2006-01-12 | ||||||||||||||||
Published: | 2006-01-12 | ||||||||||||||||
Updated: | 2018-10-30 | ||||||||||||||||
Summary: | Multiple cross-site scripting (XSS) vulnerabilities in PHP 4.4.1 and 5.1.1, when display_errors and html_errors are on, allow remote attackers to inject arbitrary web script or HTML via inputs to PHP applications that are not filtered when they are included in the resulting error message. | ||||||||||||||||
CVSS v3 Severity: | 3.7 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||||||||||
CVSS v2 Severity: | 2.6 Low (CVSS v2 Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N)
| ||||||||||||||||
Vulnerability Type: | CWE-79 | ||||||||||||||||
References: | Source: SGI Type: UNKNOWN 20060501-01-U Source: MITRE Type: CNA CVE-2006-0208 Source: SUSE Type: UNKNOWN SUSE-SR:2006:004 Source: REDHAT Type: UNKNOWN RHSA-2006:0276 Source: REDHAT Type: Vendor Advisory RHSA-2006:0549 Source: SECUNIA Type: Patch, Vendor Advisory 18431 Source: SECUNIA Type: Patch, Vendor Advisory 18697 Source: SECUNIA Type: Vendor Advisory 19012 Source: SECUNIA Type: Patch, Vendor Advisory 19179 Source: SECUNIA Type: Patch, Vendor Advisory 19355 Source: SECUNIA Type: Vendor Advisory 19832 Source: SECUNIA Type: Vendor Advisory 20210 Source: SECUNIA Type: Vendor Advisory 20222 Source: SECUNIA Type: Vendor Advisory 20951 Source: SECUNIA Type: Vendor Advisory 21252 Source: SECUNIA Type: Vendor Advisory 21564 Source: CONFIRM Type: UNKNOWN http://support.avaya.com/elmodocs2/security/ASA-2006-129.htm Source: CONFIRM Type: UNKNOWN http://support.avaya.com/elmodocs2/security/ASA-2006-160.htm Source: GENTOO Type: Patch, Vendor Advisory GLSA-200603-22 Source: MANDRIVA Type: UNKNOWN MDKSA-2006:028 Source: CONFIRM Type: UNKNOWN http://www.php.net/ChangeLog-4.php#4.4.2 Source: CONFIRM Type: Patch http://www.php.net/release_5_1_2.php Source: REDHAT Type: Vendor Advisory RHSA-2006:0501 Source: BID Type: Patch 16803 Source: VUPEN Type: Vendor Advisory ADV-2006-0177 Source: VUPEN Type: Vendor Advisory ADV-2006-0369 Source: VUPEN Type: Vendor Advisory ADV-2006-2685 Source: MISC Type: UNKNOWN https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=178028 Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:10064 Source: UBUNTU Type: UNKNOWN USN-261-1 | ||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration RedHat 1: Configuration RedHat 2: Configuration RedHat 3: Configuration RedHat 4: Configuration RedHat 5: ![]() | ||||||||||||||||
Oval Definitions | |||||||||||||||||
| |||||||||||||||||
BACK |