Vulnerabilities > CVE-2006-6389 - Scripts Multiple Cross-Site Scripting vulnerability in Mobile

047910
CVSS 6.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
ac4p
exploit available

Summary

Multiple cross-site scripting (XSS) vulnerabilities in ac4p Mobile allow remote attackers to inject arbitrary web script or HTML via the (1) Taaa parameter to (a) up.php, or the (2) pollhtml and (3) Bloks parameters to (b) polls.php, different vectors than CVE-2006-5770.

Vulnerable Configurations

Part Description Count
Application
Ac4P
1

Exploit-Db

  • descriptionac4p Mobile up.php Taaa Parameter XSS. CVE-2006-6389. Webapps exploit for php platform
    idEDB-ID:29225
    last seen2016-02-03
    modified2006-12-04
    published2006-12-04
    reporterSwEET-DeViL
    sourcehttps://www.exploit-db.com/download/29225/
    titleac4p Mobile up.php Taaa Parameter XSS
  • descriptionac4p Mobile polls.php Multiple Parameter XSS. CVE-2006-6389. Webapps exploit for php platform
    idEDB-ID:29226
    last seen2016-02-03
    modified2006-12-04
    published2006-12-04
    reporterSwEET-DeViL
    sourcehttps://www.exploit-db.com/download/29226/
    titleac4p Mobile polls.php Multiple Parameter XSS