CVE Vulnerabilities

CVE-2006-5631

Published: Oct 31, 2006 | Modified: Jul 20, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Cross-site scripting (XSS) vulnerability in change_pass.php in iG Shop 1.4 allows remote attackers to inject arbitrary web script or HTML via arbitrary query strings when the action parameter is not 1, as demonstrated using script in the action parameter, a different vulnerability than CVE-2006-5632.

Affected Software

Name Vendor Start Version End Version
Ig_shop Ig_shop 1.4 (including) 1.4 (including)

References