Vulnerabilities > CVE-2006-3009 - Cross-Site Scripting vulnerability in Aliacom Open Business Management 1.0.3Pl1
Attack vector
NETWORK Attack complexity
MEDIUM Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
PARTIAL Availability impact
NONE Summary
Multiple cross-site scripting (XSS) vulnerabilities in Open Business Management (OBM) 1.0.3 pl1 allow remote attackers to inject arbitrary HTML or web script via the (1) tf_lang, (2) tf_name, (3) tf_user, (4) tf_lastname, (5) tf_contact, (6) tf_datebefore, and (7) tf_dateafter parameters to files such as (a) publication/publication_index.php, (b) group/group_index.php, (c) user/user_index.php, (d) list/list_index.php, and (e) company/company_index.php.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description Open Business Management 1.0.3 pl1 company_index.php Multiple Parameter XSS. CVE-2006-3009. Webapps exploit for php platform id EDB-ID:27998 last seen 2016-02-03 modified 2006-06-07 published 2006-06-07 reporter r0t source https://www.exploit-db.com/download/27998/ title Open Business Management 1.0.3 pl1 company_index.php Multiple Parameter XSS description Open Business Management 1.0.3 pl1 publication_index.php tf_lang Parameter XSS. CVE-2006-3009. Webapps exploit for php platform id EDB-ID:27994 last seen 2016-02-03 modified 2006-06-07 published 2006-06-07 reporter r0t source https://www.exploit-db.com/download/27994/ title Open Business Management 1.0.3 pl1 publication_index.php tf_lang Parameter XSS description Open Business Management 1.0.3 pl1 list_index.php Multiple Parameter XSS. CVE-2006-3009. Webapps exploit for php platform id EDB-ID:27997 last seen 2016-02-03 modified 2006-06-07 published 2006-06-07 reporter r0t source https://www.exploit-db.com/download/27997/ title Open Business Management 1.0.3 pl1 list_index.php Multiple Parameter XSS description Open Business Management 1.0.3 pl1 user_index.php tf_lastname Parameter XSS. CVE-2006-3009. Webapps exploit for php platform id EDB-ID:27996 last seen 2016-02-03 modified 2006-06-07 published 2006-06-07 reporter r0t source https://www.exploit-db.com/download/27996/ title Open Business Management 1.0.3 pl1 user_index.php tf_lastname Parameter XSS description Open Business Management 1.0.3 pl1 group_index.php Multiple Parameter XSS. CVE-2006-3009 . Webapps exploit for php platform id EDB-ID:27995 last seen 2016-02-03 modified 2006-06-07 published 2006-06-07 reporter r0t source https://www.exploit-db.com/download/27995/ title Open Business Management 1.0.3 pl1 group_index.php Multiple Parameter XSS
References
- http://pridels0.blogspot.com/2006/06/obm-multiple-sql-inj-and-xss-vuln.html
- http://secunia.com/advisories/20486
- http://www.osvdb.org/26198
- http://www.osvdb.org/26199
- http://www.osvdb.org/26200
- http://www.osvdb.org/26201
- http://www.osvdb.org/26202
- http://www.securityfocus.com/bid/18348
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27031