Vulnerabilities > CVE-2006-0650 - Cross-Site Scripting vulnerability in CPAINT TYPE.PHP

047910
CVSS 4.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
cpaint
exploit available

Summary

Cross-site scripting (XSS) vulnerability in cpaint2.inc.php in the CPAINT library before 2.0.3, as used in multiple scripts, allows remote attackers to inject arbitrary web script or HTML via the cpaint_response_type parameter, which is displayed in a resulting error message, as demonstrated using a hex-encoded IFRAME tag.

Exploit-Db

descriptionCPAINT 1.3/2.0 TYPE.PHP Cross-Site Scripting Vulnerability. CVE-2006-0650 . Webapps exploit for php platform
idEDB-ID:27173
last seen2016-02-03
modified2006-02-08
published2006-02-08
reporterJames Bercegay
sourcehttps://www.exploit-db.com/download/27173/
titleCPAINT 1.3/2.0 TYPE.PHP Cross-Site Scripting Vulnerability