Vulnerabilities > CVE-2006-3052 - Cross-Site Scripting vulnerability in Event Registration 2Checkout

047910
CVSS 6.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
cescripts
exploit available

Summary

Cross-site scripting (XSS) vulnerability in Event Registration allows remote attackers to inject arbitrary web script or HTML via the (1) event_id parameter to view-event-details.php or (2) select_events parameter to event-registration.php. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

Exploit-Db

descriptionCEScripts Multiple Scripts Cross-Site Scripting Vulnerabilities. CVE-2006-3052. Webapps exploit for php platform
idEDB-ID:28017
last seen2016-02-03
modified2006-06-13
published2006-06-13
reporterLuny
sourcehttps://www.exploit-db.com/download/28017/
titleCEScripts Multiple Scripts Cross-Site Scripting Vulnerabilities