Vulnerabilities > CVE-2006-3009 - Cross-Site Scripting vulnerability in Aliacom Open Business Management 1.0.3Pl1

047910
CVSS 5.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
NONE
network
aliacom
exploit available

Summary

Multiple cross-site scripting (XSS) vulnerabilities in Open Business Management (OBM) 1.0.3 pl1 allow remote attackers to inject arbitrary HTML or web script via the (1) tf_lang, (2) tf_name, (3) tf_user, (4) tf_lastname, (5) tf_contact, (6) tf_datebefore, and (7) tf_dateafter parameters to files such as (a) publication/publication_index.php, (b) group/group_index.php, (c) user/user_index.php, (d) list/list_index.php, and (e) company/company_index.php.

Vulnerable Configurations

Part Description Count
Application
Aliacom
1

Exploit-Db

  • descriptionOpen Business Management 1.0.3 pl1 company_index.php Multiple Parameter XSS. CVE-2006-3009. Webapps exploit for php platform
    idEDB-ID:27998
    last seen2016-02-03
    modified2006-06-07
    published2006-06-07
    reporterr0t
    sourcehttps://www.exploit-db.com/download/27998/
    titleOpen Business Management 1.0.3 pl1 company_index.php Multiple Parameter XSS
  • descriptionOpen Business Management 1.0.3 pl1 publication_index.php tf_lang Parameter XSS. CVE-2006-3009. Webapps exploit for php platform
    idEDB-ID:27994
    last seen2016-02-03
    modified2006-06-07
    published2006-06-07
    reporterr0t
    sourcehttps://www.exploit-db.com/download/27994/
    titleOpen Business Management 1.0.3 pl1 publication_index.php tf_lang Parameter XSS
  • descriptionOpen Business Management 1.0.3 pl1 list_index.php Multiple Parameter XSS. CVE-2006-3009. Webapps exploit for php platform
    idEDB-ID:27997
    last seen2016-02-03
    modified2006-06-07
    published2006-06-07
    reporterr0t
    sourcehttps://www.exploit-db.com/download/27997/
    titleOpen Business Management 1.0.3 pl1 list_index.php Multiple Parameter XSS
  • descriptionOpen Business Management 1.0.3 pl1 user_index.php tf_lastname Parameter XSS. CVE-2006-3009. Webapps exploit for php platform
    idEDB-ID:27996
    last seen2016-02-03
    modified2006-06-07
    published2006-06-07
    reporterr0t
    sourcehttps://www.exploit-db.com/download/27996/
    titleOpen Business Management 1.0.3 pl1 user_index.php tf_lastname Parameter XSS
  • descriptionOpen Business Management 1.0.3 pl1 group_index.php Multiple Parameter XSS. CVE-2006-3009 . Webapps exploit for php platform
    idEDB-ID:27995
    last seen2016-02-03
    modified2006-06-07
    published2006-06-07
    reporterr0t
    sourcehttps://www.exploit-db.com/download/27995/
    titleOpen Business Management 1.0.3 pl1 group_index.php Multiple Parameter XSS