Vulnerabilities > CVE-2006-1392 - Unspecified vulnerability in University of Washington Pubcookie
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN university-of-washington
nessus
Summary
Multiple cross-site scripting (XSS) vulnerabilities in index.cgi in the login server in University of Washington Pubcookie 3.0.0, 3.1.0, 3.1.1, 3.2 before 3.2.1b, and 3.3 before 3.3.0a allow remote attackers to inject arbitrary web script or HTML via unspecified inputs.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 7 |
Nessus
NASL family | CGI abuses : XSS |
NASL id | PUBCOOKIE_XSS.NASL |
description | The remote host is running Pubcookie, an open source package for intra-institutional, single-sign-on, end-user web authentication. The version of the Login Server component of Pubcookie installed on the remote host fails to sanitize user-supplied input to various parameters of the |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 21158 |
published | 2006-03-28 |
reporter | This script is Copyright (C) 2006-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/21158 |
title | Pubcookie Login Server index.cgi XSS |
code |
|
References
- http://pubcookie.org/news/20060306-login-secadv.html
- http://pubcookie.org/news/20060306-login-secadv.html
- http://secunia.com/advisories/19348
- http://secunia.com/advisories/19348
- http://www.kb.cert.org/vuls/id/337585
- http://www.kb.cert.org/vuls/id/337585
- http://www.osvdb.org/24521
- http://www.osvdb.org/24521
- http://www.securityfocus.com/bid/17221
- http://www.securityfocus.com/bid/17221
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25427
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25427