Vulnerability Description
Cross-site scripting (XSS) vulnerability in tiki-featured_link.php in Tikiwiki 1.9.5 allows remote attackers to inject arbitrary web script or HTML via a url parameter that evades filtering, as demonstrated by a parameter value containing malformed, nested SCRIPT elements.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Tiki | Tikiwiki Cms\/Groupware | 1.9.5 |
Related Weaknesses (CWE)
References
- http://secunia.com/advisories/22678Vendor Advisory
- http://secunia.com/advisories/23039
- http://security.gentoo.org/glsa/glsa-200611-11.xml
- http://securityreason.com/securityalert/1816
- http://www.securityfocus.com/archive/1/450268/100/0/threaded
- http://www.securityfocus.com/bid/20858Exploit
- http://www.vupen.com/english/advisories/2006/4316
- https://exchange.xforce.ibmcloud.com/vulnerabilities/29958
- http://secunia.com/advisories/22678Vendor Advisory
- http://secunia.com/advisories/23039
- http://security.gentoo.org/glsa/glsa-200611-11.xml
- http://securityreason.com/securityalert/1816
- http://www.securityfocus.com/archive/1/450268/100/0/threaded
- http://www.securityfocus.com/bid/20858Exploit
- http://www.vupen.com/english/advisories/2006/4316
FAQ
What is CVE-2006-5703?
CVE-2006-5703 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Cross-site scripting (XSS) vulnerability in tiki-featured_link.php in Tikiwiki 1.9.5 allows remote attackers to inject arbitrary web script or HTML via a url parameter that evades filtering, as demons...
How severe is CVE-2006-5703?
CVE-2006-5703 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2006-5703?
Check the references section above for vendor advisories and patch information. Affected products include: Tiki Tikiwiki Cms\/Groupware.