First published: Sun Mar 26 2006(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in index.cgi in the login server in University of Washington Pubcookie 3.0.0, 3.1.0, 3.1.1, 3.2 before 3.2.1b, and 3.3 before 3.3.0a allow remote attackers to inject arbitrary web script or HTML via unspecified inputs.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
University Of Washington Pubcookie | =3.3.0 | |
University Of Washington Pubcookie | =3.2.0 | |
University Of Washington Pubcookie | =3.2.1a | |
University Of Washington Pubcookie | =3.1.0 | |
University Of Washington Pubcookie | =3.0.0 | |
University Of Washington Pubcookie | =3.1.1 | |
University Of Washington Pubcookie | =3.2.1 | |
University of Washington Pubcookie | =3.0.0 | |
University of Washington Pubcookie | =3.1.0 | |
University of Washington Pubcookie | =3.1.1 | |
University of Washington Pubcookie | =3.2.0 | |
University of Washington Pubcookie | =3.2.1 | |
University of Washington Pubcookie | =3.2.1a | |
University of Washington Pubcookie | =3.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-1392 has been classified as a moderate severity vulnerability due to its potential for cross-site scripting attacks.
To fix CVE-2006-1392, upgrade your Pubcookie installation to version 3.2.1b or later.
CVE-2006-1392 affects Pubcookie versions 3.0.0 through 3.1.1, 3.2.0, and 3.2.1 before 3.2.1b.
Yes, CVE-2006-1392 can be exploited remotely by attackers to inject arbitrary web scripts or HTML.
CVE-2006-1392 is classified as a cross-site scripting (XSS) vulnerability.