Multiple cross-site scripting (XSS) vulnerabilities in Ringlink 3.2 allow remote attackers to inject arbitrary web script or HTML via a JavaScript URI in the SRC attribute of an IMG element, and possibly other manipulations, in the ringid parameter in (1) next.cgi, (2) stats.cgi, or (3) list.cgi.
References
Configurations
History
21 Nov 2024, 00:12
Type | Values Removed | Values Added |
---|---|---|
References | () http://secunia.com/advisories/20590 - Vendor Advisory | |
References | () http://securityreason.com/securityalert/1082 - | |
References | () http://www.osvdb.org/26318 - | |
References | () http://www.osvdb.org/26319 - | |
References | () http://www.osvdb.org/26320 - | |
References | () http://www.securityfocus.com/archive/1/436690/100/0/threaded - | |
References | () http://www.securityfocus.com/bid/18360 - | |
References | () http://www.vupen.com/english/advisories/2006/2281 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/27053 - |
Information
Published : 2006-06-13 01:02
Updated : 2024-11-21 00:12
NVD link : CVE-2006-2991
Mitre link : CVE-2006-2991
CVE.ORG link : CVE-2006-2991
JSON object : View
Products Affected
ringlink
- ringlink
CWE