CVE-2006-0506: XSS
Published Feb 1, 2006
·Updated
Cross-site scripting (XSS) vulnerability in index.php in Nuked-klaN 1.7 allows remote attackers to inject arbitrary web script or HTML via the letter parameter.
Affected Software
1 affected component
Nuked-Klan Nuked-KlaN=1.7
Event History
Feb 1, 2006
CVE Published
11:02 PM
Feb 2, 2006
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-0506?
CVE-2006-0506 is classified as a medium severity vulnerability due to its cross-site scripting (XSS) potential.
2
How do I fix CVE-2006-0506?
To fix CVE-2006-0506, validate and sanitize user input in the 'letter' parameter on index.php to prevent script injection.
3
What type of attack can CVE-2006-0506 facilitate?
CVE-2006-0506 can facilitate cross-site scripting (XSS) attacks that allow remote attackers to inject malicious scripts.
4
What software versions are affected by CVE-2006-0506?
CVE-2006-0506 specifically affects Nuked-klaN version 1.7.
5
Can CVE-2006-0506 be exploited by unauthenticated users?
Yes, CVE-2006-0506 can be exploited by unauthenticated users who manipulate the vulnerable parameters.