Cross-site scripting (XSS) vulnerability in cms_images/js/htmlarea/htmlarea.php in phpFaber Content Management...
Vulnerability Description
Cross-site scripting (XSS) vulnerability in cms_images/js/htmlarea/htmlarea.php in phpFaber Content Management System (CMS) before 1.3.36 on 20061026 allows remote attackers to inject arbitrary web script or HTML, probably via arbitrary parameters in the query string, as demonstrated with a vigilon parameter. NOTE: earlier downloads of 1.3.36 have the vulnerability; the software was updated without changing the version number.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2006-5626
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.vigilon.com/advisories/vg-phpfaber-24-10-2006.txt
- http://www.vigilon.com/resources/102506c.html
- http://www.securityfocus.com/bid/20821
- http://secunia.com/advisories/22629
- http://securityreason.com/securityalert/1802
- http://www.vupen.com/english/advisories/2006/4260
- http://www.securityfocus.com/archive/1/449894/100/0/threaded
More from phpfaber
View All →Affected Vendor
phpfaber
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.