CVE-2006-1041: XSS
Multiple cross-site scripting (XSS) vulnerabilities in Gregarius 0.5.2 allow remote attackers to inject arbitrary web script or HTML via the (1) rssquery parameter to search.php or (2) tag parameter to tags.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-1041?
CVE-2006-1041 has a medium severity due to its impact on user data integrity and potential for cross-site scripting attacks.
How do I fix CVE-2006-1041?
To fix CVE-2006-1041, upgrade Gregarius to at least version 0.5.3 or later which addresses these vulnerabilities.
What are the attack vectors for CVE-2006-1041?
The attack vectors for CVE-2006-1041 include the rss_query parameter in search.php and the tag parameter in tags.php.
Who is affected by CVE-2006-1041?
Users of Gregarius version 0.5.2 are affected by CVE-2006-1041, exposing them to cross-site scripting vulnerabilities.
Can CVE-2006-1041 be exploited without user interaction?
Yes, CVE-2006-1041 can be exploited without user interaction, allowing remote attackers to inject scripts into web pages viewed by users.