{ "id": "CVE-2006-3183", "sourceIdentifier": "cve@mitre.org", "published": "2006-06-23T00:02:00.000", "lastModified": "2024-11-21T00:13:00.857", "vulnStatus": "Modified", "cveTags": [], "descriptions": [ { "lang": "en", "value": "Cross-site scripting (XSS) vulnerability in index.php in MobeScripts Mobile Space Community 2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) browse parameter, which is not filtered in the resulting error message, and multiple unspecified input fields, including those involved when (2) updating a profile, (3) posting comments or entries in a blog, (4) uploading files, (5) picture captions, and (6) sending a private message (PM)." }, { "lang": "es", "value": "Vulnerabilidades de ejecuci\u00f3n de secuencias de comandos en sitios cruzados (XSS) en index.php en MobeScripts Mobile Space Community v2.0 y anteriores, permite a atacantes remotos inyectar secuencias de comandos web o HTML a trav\u00e9s del par\u00e1metro a (1)mostrar par\u00e1metros, que no se filtra en el error resultante y m\u00faltiples campos de entrada cuando(2)se actualiza un perfil,(3)se introducen comentarios o entradas en un blog,(4) se suben ficheros, (5) se toman fotos y (6) enviando mensajes privados .\r\n" } ], "metrics": { "cvssMetricV2": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "2.0", "vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P", "baseScore": 6.8, "accessVector": "NETWORK", "accessComplexity": "MEDIUM", "authentication": "NONE", "confidentialityImpact": "PARTIAL", "integrityImpact": "PARTIAL", "availabilityImpact": "PARTIAL" }, "baseSeverity": "MEDIUM", "exploitabilityScore": 8.6, "impactScore": 6.4, "acInsufInfo": false, "obtainAllPrivilege": false, "obtainUserPrivilege": false, "obtainOtherPrivilege": true, "userInteractionRequired": false } ] }, "weaknesses": [ { "source": "nvd@nist.gov", "type": "Primary", "description": [ { "lang": "en", "value": "NVD-CWE-Other" } ] } ], "configurations": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:a:mobescripts:mobile_space_community:2.0:*:*:*:*:*:*:*", "matchCriteriaId": "C2A241A9-6882-4F81-89CA-183B5A874370" } ] } ] } ], "references": [ { "url": "http://archives.neohapsis.com/archives/bugtraq/2006-06/0115.html", "source": "cve@mitre.org" }, { "url": "http://secunia.com/advisories/20611", "source": "cve@mitre.org", "tags": [ "Vendor Advisory" ] }, { "url": "http://securityreason.com/securityalert/1128", "source": "cve@mitre.org" }, { "url": "http://www.osvdb.org/26419", "source": "cve@mitre.org" }, { "url": "http://www.vupen.com/english/advisories/2006/2312", "source": "cve@mitre.org" }, { "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/27151", "source": "cve@mitre.org" }, { "url": "http://archives.neohapsis.com/archives/bugtraq/2006-06/0115.html", "source": "af854a3a-2127-422b-91ae-364da2661108" }, { "url": "http://secunia.com/advisories/20611", "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ] }, { "url": "http://securityreason.com/securityalert/1128", "source": "af854a3a-2127-422b-91ae-364da2661108" }, { "url": "http://www.osvdb.org/26419", "source": "af854a3a-2127-422b-91ae-364da2661108" }, { "url": "http://www.vupen.com/english/advisories/2006/2312", "source": "af854a3a-2127-422b-91ae-364da2661108" }, { "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/27151", "source": "af854a3a-2127-422b-91ae-364da2661108" } ] }