{ "id": "CVE-2006-3212", "sourceIdentifier": "cve@mitre.org", "published": "2006-06-24T01:06:00.000", "lastModified": "2024-11-21T00:13:05.043", "vulnStatus": "Modified", "cveTags": [], "descriptions": [ { "lang": "en", "value": "Cross-site scripting (XSS) vulnerability in sign.php in cjGuestbook 1.3 and earlier allows remote attackers to inject web script or HTML via the (1) name, (2) email, (3) add, and (4) wName parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information." }, { "lang": "es", "value": "M\u00faltiples vulnerabilidades de ejecuci\u00f3n de secuencias de comandos en sitios cruzados (XSS) en sign.php en cjGuestbook v1.3, permite a atacantes remotos inyectar secuencias de comandos web o HTML a trav\u00e9s del par\u00e1metro (1) name, (2) email, (3) add y (4) WName. NOTA: la procedencia de esta informaci\u00f3n es desconocida, los detalles se han obtenido \u00fanicamente de informaci\u00f3n de terceros." } ], "metrics": { "cvssMetricV2": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "2.0", "vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N", "baseScore": 4.3, "accessVector": "NETWORK", "accessComplexity": "MEDIUM", "authentication": "NONE", "confidentialityImpact": "NONE", "integrityImpact": "PARTIAL", "availabilityImpact": "NONE" }, "baseSeverity": "MEDIUM", "exploitabilityScore": 8.6, "impactScore": 2.9, "acInsufInfo": false, "obtainAllPrivilege": false, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false } ] }, "weaknesses": [ { "source": "nvd@nist.gov", "type": "Primary", "description": [ { "lang": "en", "value": "NVD-CWE-Other" } ] } ], "configurations": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:a:cjguestbook:cjguestbook:*:*:*:*:*:*:*:*", "versionEndIncluding": "1.3", "matchCriteriaId": "C711815A-A4DD-4E5D-A3DB-FC7DB1F7A3F9" }, { "vulnerable": true, "criteria": "cpe:2.3:a:cjguestbook:cjguestbook:1.2:*:*:*:*:*:*:*", "matchCriteriaId": "7B40858C-7B2D-4853-9919-C02B9FD39E57" } ] } ] } ], "references": [ { "url": "http://secunia.com/advisories/20751", "source": "cve@mitre.org" }, { "url": "http://www.securityfocus.com/bid/18591", "source": "cve@mitre.org" }, { "url": "http://www.vupen.com/english/advisories/2006/2488", "source": "cve@mitre.org" }, { "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/27326", "source": "cve@mitre.org" }, { "url": "http://secunia.com/advisories/20751", "source": "af854a3a-2127-422b-91ae-364da2661108" }, { "url": "http://www.securityfocus.com/bid/18591", "source": "af854a3a-2127-422b-91ae-364da2661108" }, { "url": "http://www.vupen.com/english/advisories/2006/2488", "source": "af854a3a-2127-422b-91ae-364da2661108" }, { "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/27326", "source": "af854a3a-2127-422b-91ae-364da2661108" } ] }