Vulnerability Name: | CVE-2006-1392 (CCN-25427) | ||||||||
Assigned: | 2006-03-23 | ||||||||
Published: | 2006-03-23 | ||||||||
Updated: | 2017-07-20 | ||||||||
Summary: | Multiple cross-site scripting (XSS) vulnerabilities in index.cgi in the login server in University of Washington Pubcookie 3.0.0, 3.1.0, 3.1.1, 3.2 before 3.2.1b, and 3.3 before 3.3.0a allow remote attackers to inject arbitrary web script or HTML via unspecified inputs. | ||||||||
CVSS v3 Severity: | 3.7 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2006-1392 Source: CONFIRM Type: Patch, Vendor Advisory http://pubcookie.org/news/20060306-login-secadv.html Source: CCN Type: SA19348 Pubcookie Cross-Site Scripting Vulnerabilities Source: SECUNIA Type: Patch, Vendor Advisory 19348 Source: CCN Type: US-CERT VU#337585 Pubcookie login server contains cross-site scripting vulnerabilities Source: CERT-VN Type: Patch, Third Party Advisory, US Government Resource VU#337585 Source: OSVDB Type: UNKNOWN 24521 Source: CCN Type: OSVDB ID: 24521 Pubcookie index.cgi Unspecified XSS Source: CCN Type: Pubcookie Web site Pubcookie: open-source software for intra-institutional web authentication Source: CCN Type: Pubcookie News March 6, 2006: Pubcookie Login Server Security Advisory Source: BID Type: UNKNOWN 17221 Source: CCN Type: BID-17221 Pubcookies Multiple Cross-Site Scripting Vulnerabilities Source: XF Type: UNKNOWN pubcookie-login-server-xss(25427) Source: XF Type: UNKNOWN pubcookie-login-server-xss(25427) | ||||||||
Vulnerable Configuration: | Configuration 1:![]() | ||||||||
BACK |