Vulnerabilities > CVE-2006-4528 - Cross-Site Scripting vulnerability in Membrepass 1.5
Attack vector
NETWORK Attack complexity
MEDIUM Privileges required
NONE Confidentiality impact
NONE Integrity impact
PARTIAL Availability impact
NONE network
membrepass
Summary
Multiple cross-site scripting (XSS) vulnerabilities in membrepass 1.5 allow remote attackers to inject arbitrary web script or HTML via the (1) recherche parameter in recherchemembre.php and the (2) email parameter in test.php.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
References
- http://acid-root.new.fr/advisories/09290806.txt
- http://secunia.com/advisories/21715
- http://securityreason.com/securityalert/1487
- http://www.securityfocus.com/archive/1/444845/100/0/threaded
- http://www.securityfocus.com/bid/19789
- http://www.vupen.com/english/advisories/2006/3427
- https://exchange.xforce.ibmcloud.com/vulnerabilities/28691