{ "id": "CVE-2006-4543", "sourceIdentifier": "cve@mitre.org", "published": "2006-09-06T00:04:00.000", "lastModified": "2018-10-17T21:37:33.370", "vulnStatus": "Modified", "descriptions": [ { "lang": "en", "value": "Cross-site scripting (XSS) vulnerability in index.php in HLStats 1.34 allows remote attackers to inject arbitrary web script or HTML via the (1) game parameter in players mode, the (2) weapon parameter in weaponinfo mode, the (3) st parameter in search mode, the (4) action parameter in actioninfo mode, and the (5) map parameter in mapinfo mode." }, { "lang": "es", "value": "Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en index.php en HLStats 1.34 permite a un atacante remoto inyectar secuencias de comandos web o HTML a tra\u00b4ves del par\u00e1metro (1) game en modo juego, (2)el par\u00e1metro st en modo b\u00fasqueda, el par\u00e1metro (3) action en el modo actioninfo, y el par\u00e1metro (5) map en modo mapinfo." } ], "metrics": { "cvssMetricV2": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "2.0", "vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P", "accessVector": "NETWORK", "accessComplexity": "MEDIUM", "authentication": "NONE", "confidentialityImpact": "PARTIAL", "integrityImpact": "PARTIAL", "availabilityImpact": "PARTIAL", "baseScore": 6.8 }, "baseSeverity": "MEDIUM", "exploitabilityScore": 8.6, "impactScore": 6.4, "acInsufInfo": false, "obtainAllPrivilege": false, "obtainUserPrivilege": false, "obtainOtherPrivilege": true, "userInteractionRequired": false } ] }, "weaknesses": [ { "source": "nvd@nist.gov", "type": "Primary", "description": [ { "lang": "en", "value": "NVD-CWE-Other" } ] } ], "configurations": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:a:hlstats:hlstats:1.34:*:*:*:*:*:*:*", "matchCriteriaId": "7998CDD1-22DA-4591-8516-8E221CD6B9A1" } ] } ] } ], "references": [ { "url": "http://securityreason.com/securityalert/1490", "source": "cve@mitre.org" }, { "url": "http://www.securityfocus.com/archive/1/444716/100/0/threaded", "source": "cve@mitre.org" }, { "url": "http://www.securityfocus.com/bid/19771", "source": "cve@mitre.org", "tags": [ "Exploit" ] } ] }