Multiple cross-site scripting (XSS) vulnerabilities in PRV.php in PhpRemoteView, possibly 2003-10-23 and earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) f, (2) d, and (3) ref parameters, and the (4) "MAKE DIR" and (5) "Full file name" fields.
References
Configurations
History
21 Nov 2024, 00:11
Type | Values Removed | Values Added |
---|---|---|
References | () http://secunia.com/advisories/20141 - | |
References | () http://securityreason.com/securityalert/902 - | |
References | () http://soot.shabgard.org/bugs/phpremoteview.txt - Exploit | |
References | () http://www.osvdb.org/25572 - | |
References | () http://www.securityfocus.com/archive/1/434118/100/0/threaded - | |
References | () http://www.securityfocus.com/bid/17994 - Exploit | |
References | () http://www.vupen.com/english/advisories/2006/1844 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/26473 - |
Information
Published : 2006-05-17 10:06
Updated : 2024-11-21 00:11
NVD link : CVE-2006-2425
Mitre link : CVE-2006-2425
CVE.ORG link : CVE-2006-2425
JSON object : View
Products Affected
phpremoteview
- phpremoteview
CWE