Vulnerability Description
Multiple cross-site scripting (XSS) vulnerabilities in Dragonfly CMS before 9.0.6.1 allow remote attackers to inject arbitrary web script or HTML via (1) uname, (2) error, (3) profile or (4) the username filed parameter to the (a) Your_Account module, (5) catid, (6) sid, (7) Story Text or (8) Extended text text fields in the (b) News module, (9) month, (10) year or (11) sa parameter to the (c) Stories_Archive module, (12) show, (13) cid, (14) ratetype, or (15) orderby parameter to the (d) Web_Links module, (16) op, or (17) pollid parameter to the (e) Surveys module, (18) c parameter to the (f) Downloads module, (19) meta, or (20) album parameter to the (g) coppermine module, or the search box in the (21) Search, (22) Stories_Archive, (23) Downloads, and (24) Topics module.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cpg-Nuke | Dragonfly Cms | 9.0.1.1 |
References
- http://lostmon.blogspot.com/2006/02/multiple-cross-site-scripting-in.htmlExploitVendor Advisory
- http://secunia.com/advisories/18940Vendor Advisory
- http://securitytracker.com/id?1015661Exploit
- http://www.securityfocus.com/bid/16784Exploit
- http://www.vupen.com/english/advisories/2006/0688
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24843
- http://lostmon.blogspot.com/2006/02/multiple-cross-site-scripting-in.htmlExploitVendor Advisory
- http://secunia.com/advisories/18940Vendor Advisory
- http://securitytracker.com/id?1015661Exploit
- http://www.securityfocus.com/bid/16784Exploit
- http://www.vupen.com/english/advisories/2006/0688
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24843
FAQ
What is CVE-2006-1033?
CVE-2006-1033 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Multiple cross-site scripting (XSS) vulnerabilities in Dragonfly CMS before 9.0.6.1 allow remote attackers to inject arbitrary web script or HTML via (1) uname, (2) error, (3) profile or (4) the usern...
How severe is CVE-2006-1033?
CVE-2006-1033 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2006-1033?
Check the references section above for vendor advisories and patch information. Affected products include: Cpg-Nuke Dragonfly Cms.