Multiple cross-site scripting (XSS) vulnerabilities in index.php in ViHor Design...
Vulnerability Description
Multiple cross-site scripting (XSS) vulnerabilities in index.php in ViHor Design allow remote attackers to inject arbitrary web script or HTML via (1) a remote URL in the page parameter, which is processed by an fopen call, or (2) HTML or script in the page parameter, which is returned to the client in an error message for the failed fopen call.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2006-1496
Credits & Attribution
No credits recorded in the NVD database.
References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25483
- http://www.attrition.org/pipermail/vim/2006-March/000651.html
- http://www.securityfocus.com/archive/1/428737
- http://www.attrition.org/pipermail/vim/2006-March/000650.html
- http://secunia.com/advisories/19403
- http://www.securityfocus.com/bid/17226
Affected Vendor
vihor
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.