CVE-2006-3047: XSS
Published Jun 16, 2006
·Updated
Cross-site scripting (XSS) vulnerability in TikiWiki 1.9.3.2 and possibly earlier versions allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.
Affected Software
8 affected components
Tiki Wiki CMS Groupware=1.9.0-rc2
Tiki Wiki CMS Groupware=1.9.3
Tiki Wiki CMS Groupware=1.9.0
Tiki Wiki CMS Groupware=1.9.0-rc1
Tiki Wiki CMS Groupware=1.9.0-rc3
Tiki Wiki CMS Groupware=1.9.2
Tiki Wiki CMS Groupware=1.9.1
Tiki Wiki CMS Groupware<=1.9.3.1
Remediation
Event History
Jun 16, 2006
CVE Published
10:02 AM
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-3047?
CVE-2006-3047 is considered a medium severity vulnerability due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2006-3047?
To fix CVE-2006-3047, upgrade to a patched version of TikiWiki that addresses the XSS vulnerability.
3
Which versions of TikiWiki are affected by CVE-2006-3047?
CVE-2006-3047 affects TikiWiki version 1.9.3.2 and possibly earlier versions.
4
What type of attacks can be performed using CVE-2006-3047?
CVE-2006-3047 allows remote attackers to inject arbitrary web scripts or HTML into vulnerable TikiWiki installations.
5
Is CVE-2006-3047 easy to exploit?
Yes, CVE-2006-3047 can be easily exploited by attackers familiar with XSS techniques.