Vulnerability Description
Cross-site scripting vulnerability in index.php in raSMP 2.0.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the $_SERVER[HTTP_USER_AGENT] variable (User-Agent header).
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Rasmp | Rasmp | 2.0.0 |
References
- http://attrition.org/pipermail/vim/2006-January/000486.html
- http://evuln.com/vulns/13/summary.htmlVendor Advisory
- http://secunia.com/advisories/18292Vendor Advisory
- http://securitytracker.com/id?1015432
- http://www.osvdb.org/22198
- http://www.securityfocus.com/bid/16138
- http://www.vupen.com/english/advisories/2006/0030
- http://attrition.org/pipermail/vim/2006-January/000486.html
- http://evuln.com/vulns/13/summary.htmlVendor Advisory
- http://secunia.com/advisories/18292Vendor Advisory
- http://securitytracker.com/id?1015432
- http://www.osvdb.org/22198
- http://www.securityfocus.com/bid/16138
- http://www.vupen.com/english/advisories/2006/0030
FAQ
What is CVE-2006-0084?
CVE-2006-0084 is a vulnerability with a CVSS score of 5.0 (MEDIUM). Cross-site scripting vulnerability in index.php in raSMP 2.0.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the $_SERVER[HTTP_USER_AGENT] variable (User-Agent header)...
How severe is CVE-2006-0084?
CVE-2006-0084 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2006-0084?
Check the references section above for vendor advisories and patch information. Affected products include: Rasmp Rasmp.