Cross-site scripting (XSS) vulnerability in calendar.asp in ASPPlayground.NET Forum Advanced Edition 2.4.5 Unicode, and possibly other versions before October 15, 2006, allows remote attackers to inject arbitrary web script or HTML via the calendarID parameter.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 00:15
Type | Values Removed | Values Added |
---|---|---|
References | () http://nvd.nist.gov/nvd.cfm?cvename=CVE-2006-4206 - US Government Resource | |
References | () http://securityreason.com/securityalert/1405 - | |
References | () http://www.osvdb.org/29232 - | |
References | () http://www.securityfocus.com/archive/1/443035/100/0/threaded - | |
References | () http://www.securityfocus.com/bid/20335 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/28352 - |
Information
Published : 2006-08-17 21:04
Updated : 2024-11-21 00:15
NVD link : CVE-2006-4206
Mitre link : CVE-2006-4206
CVE.ORG link : CVE-2006-4206
JSON object : View
Products Affected
aspplayground.net
- aspplayground.net
CWE