Secunia Logo
Netsikker nu! 2008
 
CVE Reference: CVE-2006-3320
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2006-3320

Description:
Cross-site scripting (XSS) vulnerability in command.php in SiteBar 3.3.8 and earlier allows remote attackers to inject arbitrary web script or HTML via the command parameter.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/27421

SREASON
  http://securityreason.com/securityalert/1174

SAID
  Secunia Advisory: SA20841
  Secunia Advisory: SA21248

OSVDB
  26869

MISC
  http://kurdishsecurity.blogspot.com/2006/06/kurdish-security-11-sitebar-cross-site.html

DEBIAN
  http://www.debian.org/security/2006/dsa-1130

CONFIRM
  http://teamforge.net/viewcvs/viewcvs.cgi/tags/release-3.3.9/doc/history.txt?view=markup

BUGTRAQ
  http://www.securityfocus.com/archive/1/archive/1/482499/100/0/threaded
  http://www.securityfocus.com/archive/1/archive/1/438464/100/0/threaded

BID
  26126
  18680


Return to the previous page.