Vulnerability Description
Multiple cross-site scripting (XSS) vulnerabilities in index/siteforge-bugs-action/proj.siteforge in SiteForge Collaborative Development Platform 1.0.4 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) _status, (2) _extra1, (3) _extra2, or (4) _extra3 parameters.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Simian Systems Inc | Siteforge Collaborative Development Platform | <= 1.0.4 |
References
- http://pridels0.blogspot.com/2006/06/siteforge-collaborative-development_15.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27223
- http://pridels0.blogspot.com/2006/06/siteforge-collaborative-development_15.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27223
FAQ
What is CVE-2006-3521?
CVE-2006-3521 is a vulnerability with a CVSS score of 5.8 (MEDIUM). Multiple cross-site scripting (XSS) vulnerabilities in index/siteforge-bugs-action/proj.siteforge in SiteForge Collaborative Development Platform 1.0.4 and earlier allow remote attackers to inject arb...
How severe is CVE-2006-3521?
CVE-2006-3521 has been rated MEDIUM with a CVSS base score of 5.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2006-3521?
Check the references section above for vendor advisories and patch information. Affected products include: Simian Systems Inc Siteforge Collaborative Development Platform.