Vulnerabilities > CVE-2006-1295 - Unspecified vulnerability in Spip 1.8.2E/1.8.2G
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Cross-site scripting (XSS) vulnerability in recherche.php3 in SPIP 1.8.2-g allows remote attackers to inject arbitrary web script or HTML via the recherche parameter.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 2 |
References
- http://www.securityfocus.com/bid/17130
- http://www.securityfocus.com/bid/17130
- http://www.silitix.com/spip-xss.html
- http://www.silitix.com/spip-xss.html
- http://www.zone-h.fr/advisories/read/id=1105
- http://www.zone-h.fr/advisories/read/id=1105
- http://zone.spip.org/trac/spip-zone/changeset/1672
- http://zone.spip.org/trac/spip-zone/changeset/1672
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25389
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25389