Back to Database
Status published
Medium
CVE-2006-2699
Cross-site scripting (XSS) vulnerability in getimage.php in Geeklog 1.4.0sr2 and...
Vulnerability Description
Cross-site scripting (XSS) vulnerability in getimage.php in Geeklog 1.4.0sr2 and earlier allows remote attackers to inject arbitrary HTML or web script via the image argument in a show action.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2006-2699
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.geeklog.net/index.php?topic=Security
- http://securityreason.com/securityalert/993
- http://www.securityfocus.com/archive/1/435295/100/0/threaded
- http://www.vupen.com/english/advisories/2006/2050
- https://exchange.xforce.ibmcloud.com/vulnerabilities/26862
- http://kapda.ir/advisory-336.html
- http://secunia.com/advisories/20316
- http://www.securityfocus.com/bid/18154
More from geeklog
View All →CVE-2013-1470
Cross-site scripting (XSS) vulnerability in calendar/index.php in the Calendar plugin...
Medium
4.3
CVE-2011-5159
Cross-site scripting (XSS) vulnerability in admin/configuration.php in Geeklog before 1.7.1sr1...
Medium
4.3
CVE-2011-4942
Multiple cross-site scripting (XSS) vulnerabilities in admin/configuration.php in Geeklog before...
Medium
4.3
CVE-2011-4647
Multiple cross-site scripting (XSS) vulnerabilities in the story creation feature...
Medium
4.3
CVE-2010-4933
SQL injection vulnerability in filemgmt/singlefile.php in Geeklog 1.3.8 allows remote...
High
7.5
Affected Vendor
geeklog
View all reports →Affected Software
geeklog
Vulnerable Versions:
1.3, 1.3.5, 1.3.5_sr1, 1.3.6, 1.3.7, 1.3.7_sr1, 1.3.7_sr2, 1.3.7_sr3, 1.3.7_sr4, 1.3.7_sr5, 1.3.8, 1.3.8_1, 1.3.8_1_sr1, 1.3.8_1_sr2, 1.3.8_1_sr3, 1.3.8_1_sr4, 1.3.8_1_sr5, 1.3.8_1_sr6, 1.3.9, 1.3.9_rc1, 1.3.9_rc2, 1.3.9_rc3, 1.3.9_sr1, 1.3.9_sr2, 1.3.9_sr3, 1.3.9_sr4, 1.3.10, 1.3.10_rc1, 1.3.10_rc2, 1.3.10_rc3, 1.3.11, 1.3.11_rc1, 1.3.11_sr1, 1.3.11_sr2, 1.3.11_sr3, 1.3.11_sr4, 1.4.0, 1.4.0_beta1, 1.4.0_sr1, 1.4.0_sr2, 1.35
Timeline
Official Publish:
May 31st, 2006
Last Modified:
August 7th, 2024
Added to House:
July 18th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.