Vulnerability Description
Cross-site scripting (XSS) vulnerability in recherche.php3 in SPIP 1.8.2-g allows remote attackers to inject arbitrary web script or HTML via the recherche parameter.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Spip | Spip | 1.8.2e |
References
- http://www.securityfocus.com/bid/17130
- http://www.silitix.com/spip-xss.html
- http://www.zone-h.fr/advisories/read/id=1105
- http://zone.spip.org/trac/spip-zone/changeset/1672Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25389
- http://www.securityfocus.com/bid/17130
- http://www.silitix.com/spip-xss.html
- http://www.zone-h.fr/advisories/read/id=1105
- http://zone.spip.org/trac/spip-zone/changeset/1672Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25389
FAQ
What is CVE-2006-1295?
CVE-2006-1295 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Cross-site scripting (XSS) vulnerability in recherche.php3 in SPIP 1.8.2-g allows remote attackers to inject arbitrary web script or HTML via the recherche parameter.
How severe is CVE-2006-1295?
CVE-2006-1295 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2006-1295?
Check the references section above for vendor advisories and patch information. Affected products include: Spip Spip.