Vulnerabilities > CVE-2006-2648 - Cross-Site Scripting vulnerability in ASPBB Perform_search.ASP
Attack vector
NETWORK Attack complexity
HIGH Privileges required
NONE Confidentiality impact
NONE Integrity impact
PARTIAL Availability impact
NONE Summary
Cross-site scripting (XSS) vulnerability in perform_search.asp for ASPBB 0.52 and earlier allows remote attackers to inject arbitrary HTML or web script via the search parameter.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 10 |
Exploit-Db
description | ASPBB 0.5.2 Perform_search.ASP Cross-Site Scripting Vulnerability. CVE-2006-2648. Webapps exploit for asp platform |
id | EDB-ID:27918 |
last seen | 2016-02-03 |
modified | 2006-05-29 |
published | 2006-05-29 |
reporter | Mustafa Can Bjorn |
source | https://www.exploit-db.com/download/27918/ |
title | ASPBB 0.5.2 Perform_search.ASP Cross-Site Scripting Vulnerability |
References
- http://secunia.com/advisories/20360
- http://securityreason.com/securityalert/983
- http://securitytracker.com/id?1016169
- http://www.nukedx.com/?viewdoc=32
- http://www.securityfocus.com/archive/1/435280/100/0/threaded
- http://www.securityfocus.com/bid/18146
- http://www.vupen.com/english/advisories/2006/2027
- https://exchange.xforce.ibmcloud.com/vulnerabilities/26819