Vulnerabilities > CVE-2006-0894 - Unspecified vulnerability in Nocc 1.0
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Multiple cross-site scripting (XSS) vulnerabilities in NOCC Webmail 1.0 allow remote attackers to inject arbitrary web script or HTML via (1) the html_error_occurred parameter in error.php, (2) html_filter_select parameter in filter_prefs.php, (3) html_no_mail parameter in no_mail.php, the (4) page_line, (5) prev, and (6) next parameters in html_bottom_table.php, and the (7) _SESSION['nocc_theme'] parameter in footer.php.
Exploit-Db
description NOCC 1.0 html_bottom_table.php Multiple Parameter XSS. CVE-2006-0894. Webapps exploit for php platform id EDB-ID:27302 last seen 2016-02-03 modified 2006-02-23 published 2006-02-23 reporter rgod source https://www.exploit-db.com/download/27302/ title NOCC 1.0 html_bottom_table.php Multiple Parameter XSS description NOCC 1.0 no_mail.php html_no_mail Parameter XSS. CVE-2006-0894. Webapps exploit for php platform id EDB-ID:27301 last seen 2016-02-03 modified 2006-02-23 published 2006-02-23 reporter rgod source https://www.exploit-db.com/download/27301/ title NOCC 1.0 no_mail.php html_no_mail Parameter XSS description NOCC 1.0 filter_prefs.php html_filter_select Parameter XSS. CVE-2006-0894 . Webapps exploit for php platform id EDB-ID:27300 last seen 2016-02-03 modified 2006-02-23 published 2006-02-23 reporter rgod source https://www.exploit-db.com/download/27300/ title NOCC 1.0 filter_prefs.php html_filter_select Parameter XSS description NOCC 1.0 error.php html_error_occurred Parameter XSS. CVE-2006-0894 . Webapps exploit for php platform id EDB-ID:27299 last seen 2016-02-03 modified 2006-02-23 published 2006-02-23 reporter rgod source https://www.exploit-db.com/download/27299/ title NOCC 1.0 error.php html_error_occurred Parameter XSS
Nessus
NASL family | CGI abuses |
NASL id | NOCC_10.NASL |
description | The remote host is running NOCC, an open source webmail application written in PHP. The installed version of NOCC is affected by a local file include flaw because it fails to sanitize user input to the |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 20974 |
published | 2006-02-25 |
reporter | This script is Copyright (C) 2006-2018 and is owned by Tenable, Inc. or an Affiliate thereof. |
source | https://www.tenable.com/plugins/nessus/20974 |
title | NOCC <= 1.0 Multiple Vulnerabilities |
code |
|
References
- http://archives.neohapsis.com/archives/bugtraq/2006-02/0418.html
- http://archives.neohapsis.com/archives/bugtraq/2006-02/0418.html
- http://retrogod.altervista.org/noccw_10_incl_xpl.html
- http://retrogod.altervista.org/noccw_10_incl_xpl.html
- http://secunia.com/advisories/16921
- http://secunia.com/advisories/16921
- http://securitytracker.com/id?1015671
- http://securitytracker.com/id?1015671
- http://www.osvdb.org/23423
- http://www.osvdb.org/23423
- http://www.osvdb.org/23424
- http://www.osvdb.org/23424
- http://www.osvdb.org/23425
- http://www.osvdb.org/23425
- http://www.osvdb.org/23426
- http://www.osvdb.org/23426
- http://www.osvdb.org/23427
- http://www.osvdb.org/23427
- http://www.securityfocus.com/bid/16793
- http://www.securityfocus.com/bid/16793