Multiple unspecified cross-site scripting (XSS) vulnerabilities in Taskjitsu 2.0.3 allow...
Vulnerability Description
Multiple unspecified cross-site scripting (XSS) vulnerabilities in Taskjitsu 2.0.3 allow remote attackers to inject arbitrary web script or HTML via (1) the Search Tasks system, or authenticated users via (2) the Edit Task system, (3) the back-end Category Editor system, and (4) "Pages that display task status, email addresses, URL, customer, and project information."
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2006-3958
Credits & Attribution
No credits recorded in the NVD database.
References
- https://www.pkrinternet.com/taskjitsu/task/3477
- http://www.securityfocus.com/bid/19251
- http://www.pkrinternet.com/download/RELEASE-NOTES.txt
- http://www.vupen.com/english/advisories/2006/3058
- http://www.osvdb.org/27637
- http://secunia.com/advisories/21242
- https://exchange.xforce.ibmcloud.com/vulnerabilities/28178
More from pkr internet
View All →Affected Vendor
pkr internet
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.