CVE-2006-2419: XSS
Published May 16, 2006
·Updated
Cross-site scripting (XSS) vulnerability in index.php in Directory Listing Script allows remote attackers to inject arbitrary web script or HTML via the dir parameter.
Affected Software
1 affected component
PHP Directory Listing Script
Event History
May 16, 2006
CVE Published
10:02 AM
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-2419?
The severity of CVE-2006-2419 is classified as high due to its potential for exploitation via cross-site scripting.
2
How do I fix CVE-2006-2419?
To fix CVE-2006-2419, you should validate and sanitize user inputs, particularly the dir parameter in index.php.
3
What software is affected by CVE-2006-2419?
CVE-2006-2419 affects the Php Directory Listing Script, which is identified by the specific CPE entry.
4
What is the impact of exploiting CVE-2006-2419?
Exploiting CVE-2006-2419 can allow attackers to execute arbitrary web scripts or HTML on the client side.
5
Who can become a victim of CVE-2006-2419?
Any user accessing a vulnerable installation of the Directory Listing Script could become a victim of CVE-2006-2419.