Vulnerabilities > CVE-2006-2473 - Unspecified vulnerability in Openwiki 0.78

047910
CVSS 0.0 - NONE
Attack vector
UNKNOWN
Attack complexity
UNKNOWN
Privileges required
UNKNOWN
Confidentiality impact
UNKNOWN
Integrity impact
UNKNOWN
Availability impact
UNKNOWN
openwiki
exploit available

Summary

Cross-site scripting (XSS) vulnerability in ow.asp in OpenWiki 0.78 allows remote attackers to inject arbitrary web script or HTML via the p parameter. NOTE: this issue has been disputed by the vendor and a third party who is affiliated with the product. The vendor states "You cannot insert code in a wikipage or via URL parameters as they are all escaped before usage, so nothing can be compromised at other sites.

Vulnerable Configurations

Part Description Count
Application
Openwiki
1

Exploit-Db

descriptionOpen Wiki 0.78 'ow.asp' Cross-Site Scripting Vulnerability. CVE-2006-2473. Webapps exploit for asp platform
idEDB-ID:27890
last seen2016-02-03
modified2006-05-17
published2006-05-17
reporterLiNuX_rOOt
sourcehttps://www.exploit-db.com/download/27890/
titleOpen Wiki 0.78 - 'ow.asp' Cross-Site Scripting Vulnerability