First published: Wed Feb 15 2006(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in bbcodes system in e107 before 0.7.2 allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
e107 CMS | =0.551_beta | |
e107 CMS | =0.6175 | |
e107 CMS | =0.616 | |
e107 CMS | =0.6174 | |
e107 CMS | =5.05 | |
e107 CMS | =0.549_beta | |
e107 CMS | =0.615a | |
e107 CMS | =0.555_beta | |
e107 CMS | =0.6173 | |
e107 CMS | =0.610 | |
e107 CMS | =0.607 | |
e107 CMS | =0.609 | |
e107 CMS | =5.4_beta6 | |
e107 CMS | =0.606 | |
e107 CMS | =0.602 | |
e107 CMS | =0.7 | |
e107 CMS | =0.554_beta | |
e107 CMS | =0.7.1 | |
e107 CMS | =0.553_beta | |
e107 CMS | =0.600 | |
e107 CMS | =0.552_beta | |
e107 CMS | =0.615 | |
e107 CMS | =0.613 | |
e107 CMS | =0.604 | |
e107 CMS | =5.4_beta3 | |
e107 CMS | =0.603 | |
e107 CMS | =5.4_beta1 | |
e107 CMS | =0.614 | |
e107 CMS | =0.6172 | |
e107 CMS | =0.547_beta | |
e107 CMS | =5.2 | |
e107 CMS | =0.601 | |
e107 CMS | =5.3_beta2 | |
e107 CMS | =0.608 | |
e107 CMS | =0.548_beta | |
e107 CMS | =0.611 | |
e107 CMS | =5.4_beta4 | |
e107 CMS | =0.605 | |
e107 CMS | =5.3_beta | |
e107 CMS | =5.4_beta5 | |
e107 CMS | =0.617 | |
e107 CMS | =0.612 | |
e107 CMS | =5.1 | |
e107 CMS | =5.04 | |
e107 CMS | =0.6171 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-0682 has moderate severity due to its potential to allow attackers to execute arbitrary scripts in the context of a user's session.
To fix CVE-2006-0682, upgrade to a version of e107 CMS that is 0.7.2 or higher to mitigate the cross-site scripting vulnerabilities.
CVE-2006-0682 affects multiple versions of e107 CMS, specifically those prior to 0.7.2.
CVE-2006-0682 is classified as a cross-site scripting (XSS) vulnerability, allowing injection of malicious web scripts.
Yes, CVE-2006-0682 can be exploited remotely by attackers to carry out XSS attacks.