CVE-2006-0518: XSS
Published Feb 2, 2006
·Updated
Cross-site scripting (XSS) vulnerability in index.php3 in SPIP 1.8.2-e and earlier and 1.9 Alpha 2 (5539) and earlier allows remote attackers to inject arbitrary web script or HTML via the lang parameter.
Affected Software
2 affected components
Spip SPIP<=1.8.2e
Spip SPIP<=1.9_alpha2_5539
Event History
Feb 2, 2006
CVE Published
11:02 AM
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-0518?
CVE-2006-0518 has a moderate severity rating due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2006-0518?
To fix CVE-2006-0518, upgrade your SPIP installation to version 1.9 or later.
3
What versions of SPIP are affected by CVE-2006-0518?
CVE-2006-0518 affects SPIP versions 1.8.2-e and earlier as well as 1.9 Alpha 2 (5539) and earlier.
4
What is a cross-site scripting (XSS) vulnerability in CVE-2006-0518?
A cross-site scripting vulnerability like CVE-2006-0518 allows attackers to inject malicious scripts into web pages viewed by users.
5
Can CVE-2006-0518 allow remote attacks?
Yes, CVE-2006-0518 allows remote attackers to inject arbitrary web scripts or HTML via the lang parameter.