CVE-2006-5190 : Detail

CVE-2006-5190

7.58%V4
Network
2006-10-06
17h00 +00:00
2017-10-04
07h57 +00:00
Notifications for a CVE
Stay informed of any changes for a specific CVE.
Notifications manage

CVE Descriptions

Multiple cross-site scripting (XSS) vulnerabilities in osCommerce 2.2 Milestone 2 Update 060817 allow remote attackers to inject arbitrary web script or HTML via the (1) page parameter in the (a) banner_manager.php, (b) banner_statistics.php, (c) countries.php, (d) currencies.php, (e) languages.php, (f) manufacturers.php, (g) newsletters.php, (h) orders_status.php, (i) products_attributes.php, (j) products_expected.php, (k) reviews.php, (l) specials.php, (m) stats_products_purchased.php, (n) stats_products_viewed.php, (o) tax_classes.php, (p) tax_rates.php, or (q) zones.php scripts in /admin, and the (2) zpage parameter in (r) admin/geo_zones.php.

CVE Informations

Metrics

Metrics Score Severity CVSS Vector Source
V2 4.3 AV:N/AC:M/Au:N/C:N/I:P/A:N nvd@nist.gov

EPSS

EPSS is a scoring model that predicts the likelihood of a vulnerability being exploited.

EPSS Score

The EPSS model produces a probability score between 0 and 1 (0 and 100%). The higher the score, the greater the probability that a vulnerability will be exploited.

EPSS Percentile

The percentile is used to rank CVE according to their EPSS score. For example, a CVE in the 95th percentile according to its EPSS score is more likely to be exploited than 95% of other CVE. Thus, the percentile is used to compare the EPSS score of a CVE with that of other CVE.

Exploit information

Exploit Database EDB-ID : 28743

Publication date : 2006-10-03 22h00 +00:00
Author : Lostmon
EDB Verified : Yes

Exploit Database EDB-ID : 28744

Publication date : 2006-10-03 22h00 +00:00
Author : Lostmon
EDB Verified : Yes

Exploit Database EDB-ID : 28745

Publication date : 2006-10-03 22h00 +00:00
Author : Lostmon
EDB Verified : Yes

Exploit Database EDB-ID : 28746

Publication date : 2006-10-03 22h00 +00:00
Author : Lostmon
EDB Verified : Yes

Exploit Database EDB-ID : 28747

Publication date : 2006-10-03 22h00 +00:00
Author : Lostmon
EDB Verified : Yes

Exploit Database EDB-ID : 28748

Publication date : 2006-10-03 22h00 +00:00
Author : Lostmon
EDB Verified : Yes

Exploit Database EDB-ID : 28749

Publication date : 2006-10-03 22h00 +00:00
Author : Lostmon
EDB Verified : Yes

Exploit Database EDB-ID : 28750

Publication date : 2006-10-03 22h00 +00:00
Author : Lostmon
EDB Verified : Yes

Exploit Database EDB-ID : 28751

Publication date : 2006-10-03 22h00 +00:00
Author : Lostmon
EDB Verified : Yes

Exploit Database EDB-ID : 28752

Publication date : 2006-10-03 22h00 +00:00
Author : Lostmon
EDB Verified : Yes

Exploit Database EDB-ID : 28753

Publication date : 2006-10-03 22h00 +00:00
Author : Lostmon
EDB Verified : Yes

Exploit Database EDB-ID : 28754

Publication date : 2006-10-03 22h00 +00:00
Author : Lostmon
EDB Verified : Yes

Exploit Database EDB-ID : 28755

Publication date : 2006-10-03 22h00 +00:00
Author : Lostmon
EDB Verified : Yes

Exploit Database EDB-ID : 28756

Publication date : 2006-10-03 22h00 +00:00
Author : Lostmon
EDB Verified : Yes

Exploit Database EDB-ID : 28757

Publication date : 2006-10-03 22h00 +00:00
Author : Lostmon
EDB Verified : Yes

Exploit Database EDB-ID : 28758

Publication date : 2006-10-03 22h00 +00:00
Author : Lostmon
EDB Verified : Yes

Exploit Database EDB-ID : 28759

Publication date : 2006-10-03 22h00 +00:00
Author : Lostmon
EDB Verified : Yes

Products Mentioned

Configuraton 0

Oscommerce>>Oscommerce >> Version To (including) 2.2_ms2_2006-08-17

Oscommerce>>Oscommerce >> Version 1.1

Oscommerce>>Oscommerce >> Version 1.5.1

Oscommerce>>Oscommerce >> Version 1.11

Oscommerce>>Oscommerce >> Version 1.12

Oscommerce>>Oscommerce >> Version 1.13

Oscommerce>>Oscommerce >> Version 2.1

Oscommerce>>Oscommerce >> Version 2.2_cvs

Oscommerce>>Oscommerce >> Version 2.2_ms1

Oscommerce>>Oscommerce >> Version 2.2_ms2

Oscommerce>>Oscommerce >> Version 2.2_ms3

References

https://www.exploit-db.com/exploits/28750/
Tags : exploit, x_refsource_EXPLOIT-DB
http://www.osvdb.org/29801
Tags : vdb-entry, x_refsource_OSVDB
https://www.exploit-db.com/exploits/28746/
Tags : exploit, x_refsource_EXPLOIT-DB
http://www.osvdb.org/29803
Tags : vdb-entry, x_refsource_OSVDB
http://www.vupen.com/english/advisories/2006/3917
Tags : vdb-entry, x_refsource_VUPEN
http://www.osvdb.org/29798
Tags : vdb-entry, x_refsource_OSVDB
http://www.osvdb.org/29808
Tags : vdb-entry, x_refsource_OSVDB
http://www.osvdb.org/29807
Tags : vdb-entry, x_refsource_OSVDB
http://secunia.com/advisories/22275
Tags : third-party-advisory, x_refsource_SECUNIA
http://www.osvdb.org/29802
Tags : vdb-entry, x_refsource_OSVDB
http://www.osvdb.org/29795
Tags : vdb-entry, x_refsource_OSVDB
https://www.exploit-db.com/exploits/28759/
Tags : exploit, x_refsource_EXPLOIT-DB
https://www.exploit-db.com/exploits/28755/
Tags : exploit, x_refsource_EXPLOIT-DB
https://www.exploit-db.com/exploits/28747/
Tags : exploit, x_refsource_EXPLOIT-DB
https://www.exploit-db.com/exploits/28744/
Tags : exploit, x_refsource_EXPLOIT-DB
http://securitytracker.com/id?1016979
Tags : vdb-entry, x_refsource_SECTRACK
http://www.osvdb.org/29809
Tags : vdb-entry, x_refsource_OSVDB
http://www.osvdb.org/29799
Tags : vdb-entry, x_refsource_OSVDB
https://www.exploit-db.com/exploits/28757/
Tags : exploit, x_refsource_EXPLOIT-DB
https://www.exploit-db.com/exploits/28748/
Tags : exploit, x_refsource_EXPLOIT-DB
http://www.osvdb.org/29810
Tags : vdb-entry, x_refsource_OSVDB
http://www.osvdb.org/29811
Tags : vdb-entry, x_refsource_OSVDB
https://www.exploit-db.com/exploits/28758/
Tags : exploit, x_refsource_EXPLOIT-DB
https://www.exploit-db.com/exploits/28753/
Tags : exploit, x_refsource_EXPLOIT-DB
http://www.osvdb.org/29797
Tags : vdb-entry, x_refsource_OSVDB
http://www.osvdb.org/29806
Tags : vdb-entry, x_refsource_OSVDB
https://www.exploit-db.com/exploits/28749/
Tags : exploit, x_refsource_EXPLOIT-DB
http://www.osvdb.org/29800
Tags : vdb-entry, x_refsource_OSVDB
http://www.securityfocus.com/bid/20343
Tags : vdb-entry, x_refsource_BID
http://www.osvdb.org/29796
Tags : vdb-entry, x_refsource_OSVDB
https://www.exploit-db.com/exploits/28743/
Tags : exploit, x_refsource_EXPLOIT-DB
https://www.exploit-db.com/exploits/28754/
Tags : exploit, x_refsource_EXPLOIT-DB
https://www.exploit-db.com/exploits/28745/
Tags : exploit, x_refsource_EXPLOIT-DB
http://www.osvdb.org/29804
Tags : vdb-entry, x_refsource_OSVDB
https://www.exploit-db.com/exploits/28756/
Tags : exploit, x_refsource_EXPLOIT-DB
http://www.osvdb.org/29805
Tags : vdb-entry, x_refsource_OSVDB
https://www.exploit-db.com/exploits/28752/
Tags : exploit, x_refsource_EXPLOIT-DB