Vulnerabilities > CVE-2006-3883 - Input Validation vulnerability in Gonafish Linkscaffe 3.0

047910
CVSS 4.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
gonafish
exploit available

Summary

Multiple cross-site scripting (XSS) vulnerabilities in Gonafish LinksCaffe 3.0 allow remote attackers to inject arbitrary web script or HTML via (1) the tablewidth parameter in (a) counter.php; (2) the newdays parameter in (b) links.php; and the (3) tableborder, (4) menucolor, (5) textcolor, and (6) bodycolor parameters in (c) menu.inc.php.

Vulnerable Configurations

Part Description Count
Application
Gonafish
1

Exploit-Db

  • descriptionLinksCaffe 3.0 links.php newdays Parameter XSS. CVE-2006-3883. Webapps exploit for php platform
    idEDB-ID:28269
    last seen2016-02-03
    modified2006-07-25
    published2006-07-25
    reportersimo64
    sourcehttps://www.exploit-db.com/download/28269/
    titleLinksCaffe 3.0 links.php newdays Parameter XSS
  • descriptionLinksCaffe 3.0 counter.php tablewidth Parameter XSS. CVE-2006-3883. Webapps exploit for php platform
    idEDB-ID:28268
    last seen2016-02-03
    modified2006-07-25
    published2006-07-25
    reportersimo64
    sourcehttps://www.exploit-db.com/download/28268/
    titleLinksCaffe 3.0 counter.php tablewidth Parameter XSS
  • descriptionLinksCaffe 3.0 menu.inc.php Multiple Parameter XSS. CVE-2006-3883. Webapps exploit for php platform
    idEDB-ID:28270
    last seen2016-02-03
    modified2006-07-25
    published2006-07-25
    reportersimo64
    sourcehttps://www.exploit-db.com/download/28270/
    titleLinksCaffe 3.0 menu.inc.php Multiple Parameter XSS