First published: Tue May 16 2006(Updated: )
Cross-site scripting (XSS) vulnerability in index.php in Directory Listing Script allows remote attackers to inject arbitrary web script or HTML via the dir parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Php Directory Listing Script |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2006-2419 is classified as high due to its potential for exploitation via cross-site scripting.
To fix CVE-2006-2419, you should validate and sanitize user inputs, particularly the dir parameter in index.php.
CVE-2006-2419 affects the Php Directory Listing Script, which is identified by the specific CPE entry.
Exploiting CVE-2006-2419 can allow attackers to execute arbitrary web scripts or HTML on the client side.
Any user accessing a vulnerable installation of the Directory Listing Script could become a victim of CVE-2006-2419.