Vulnerabilities > CVE-2006-4796 - Cross-Site Scripting vulnerability in Snitz Communications Snitz Forums 2000 3.4.06

047910
CVSS 4.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
snitz-communications
exploit available

Summary

Cross-site scripting (XSS) vulnerability in forum.asp in Snitz Forums 2000 3.4.06 allows remote attackers to inject arbitrary web script or HTML via the sortorder parameter (strtopicsortord variable).

Vulnerable Configurations

Part Description Count
Application
Snitz_Communications
1

Exploit-Db

descriptionSnitz Forums 2000 Forum.ASP Cross-Site Scripting Vulnerability. CVE-2006-4796. Webapps exploit for asp platform
idEDB-ID:28566
last seen2016-02-03
modified2006-09-13
published2006-09-13
reporterajann
sourcehttps://www.exploit-db.com/download/28566/
titleSnitz Forums 2000 Forum.ASP Cross-Site Scripting Vulnerability