Vulnerabilities > CVE-2006-6640 - Cross-Site Scripting vulnerability in Omniture Sitecatalyst 0

047910
CVSS 6.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
omniture
exploit available

Summary

Multiple cross-site scripting (XSS) vulnerabilities in Omniture SiteCatalyst allow remote attackers to inject arbitrary web script or HTML via the (1) ss parameter in (a) search.asp and the (2) company and (3) username fields on (b) the web login page. NOTE: some details were obtained from third party information.

Vulnerable Configurations

Part Description Count
Application
Omniture
1

Exploit-Db

descriptionOmniture SiteCatalyst Multiple Cross-Site Scripting Vulnerabilities. CVE-2006-6640. Webapps exploit for asp platform
idEDB-ID:29288
last seen2016-02-03
modified2006-12-16
published2006-12-16
reporterHackers Center Security
sourcehttps://www.exploit-db.com/download/29288/
titleOmniture SiteCatalyst Multiple Cross-Site Scripting Vulnerabilities