CVE Vulnerabilities

CVE-2006-0650

Published: Feb 13, 2006 | Modified: Oct 19, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

Cross-site scripting (XSS) vulnerability in cpaint2.inc.php in the CPAINT library before 2.0.3, as used in multiple scripts, allows remote attackers to inject arbitrary web script or HTML via the cpaint_response_type parameter, which is displayed in a resulting error message, as demonstrated using a hex-encoded IFRAME tag.

Affected Software

Name Vendor Start Version End Version
Cpaint Cpaint 1.0 (including) 1.0 (including)
Cpaint Cpaint 1.01 (including) 1.01 (including)
Cpaint Cpaint 1.2 (including) 1.2 (including)
Cpaint Cpaint 1.3 (including) 1.3 (including)
Cpaint Cpaint 1.3_sp (including) 1.3_sp (including)
Cpaint Cpaint 1.3_sp1 (including) 1.3_sp1 (including)
Cpaint Cpaint 2.0.0 (including) 2.0.0 (including)
Cpaint Cpaint 2.0.1 (including) 2.0.1 (including)
Cpaint Cpaint 2.0.2 (including) 2.0.2 (including)
Cpaint Cpaint pre1.0 (including) pre1.0 (including)

References