CVE-2006-1673: XSS
Published Apr 7, 2006
·Updated
Cross-site scripting (XSS) vulnerability in vbugs.php in DarkWizard vBug Tracker 3.5.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the sortorder parameter.
Affected Software
1 affected component
Jelsoft Vbug Tracker<=3.5.1
Event History
Apr 7, 2006
CVE Published
10:04 AM
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-1673?
CVE-2006-1673 is classified as a high severity cross-site scripting (XSS) vulnerability.
2
How do I fix CVE-2006-1673?
To fix CVE-2006-1673, update Dark_Wizard vBug Tracker to version 3.5.2 or later.
3
What software is affected by CVE-2006-1673?
CVE-2006-1673 affects Dark_Wizard vBug Tracker versions 3.5.1 and earlier.
4
How can attackers exploit CVE-2006-1673?
Attackers can exploit CVE-2006-1673 by injecting arbitrary web scripts or HTML through the sortorder parameter.
5
What are the consequences of CVE-2006-1673?
The consequences of CVE-2006-1673 may include unauthorized script execution, potentially leading to theft of session cookies or site content.