Vulnerability Description
Multiple cross-site scripting (XSS) vulnerabilities in Chipmunk Blogger allow remote authenticated users to inject arbitrary web script or HTML via script tags in (1) posts and (2) profile names; and (3) a javascript URI in a URL argument in the photo gallery.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Chipmunk Scripts | Chipmunk Blogger | All versions |
References
- http://archives.neohapsis.com/archives/bugtraq/2006-05/0104.html
- http://securityreason.com/securityalert/2306
- http://www.securityfocus.com/bid/17862
- https://exchange.xforce.ibmcloud.com/vulnerabilities/26296
- http://archives.neohapsis.com/archives/bugtraq/2006-05/0104.html
- http://securityreason.com/securityalert/2306
- http://www.securityfocus.com/bid/17862
- https://exchange.xforce.ibmcloud.com/vulnerabilities/26296
FAQ
What is CVE-2006-7043?
CVE-2006-7043 is a vulnerability with a CVSS score of 3.5 (LOW). Multiple cross-site scripting (XSS) vulnerabilities in Chipmunk Blogger allow remote authenticated users to inject arbitrary web script or HTML via script tags in (1) posts and (2) profile names; and ...
How severe is CVE-2006-7043?
CVE-2006-7043 has been rated LOW with a CVSS base score of 3.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2006-7043?
Check the references section above for vendor advisories and patch information. Affected products include: Chipmunk Scripts Chipmunk Blogger.