Vulnerabilities > CVE-2006-7061 - Cross-Site Scripting vulnerability in E-Dating System

047910
CVSS 9.3 - CRITICAL
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
scriptsez-net
critical

Summary

Scriptsez.net E-Dating System stores data files with predictable names under the web document root with insufficient access control, which allows remote attackers to read private messages and leverage them for cross-site scripting (XSS) attacks.

Vulnerable Configurations

Part Description Count
Application
Scriptsez.Net
1