First published: Tue Jun 27 2006(Updated: )
Cross-site scripting (XSS) vulnerability in index.tmpl in Azureus Tracker 2.4.0.2 and earlier (Java BitTorrent Client Tracker) allows remote attackers to inject arbitrary web script or HTML via the search parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
The Foreman | =2.2.0.2 | |
The Foreman | =2.3.0.6 | |
The Foreman | =2.4.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-3230 is categorized as a high severity vulnerability due to its potential for exploiting cross-site scripting (XSS).
To fix CVE-2006-3230, upgrade to Azureus Tracker version 2.4.0.3 or later, which addresses the XSS vulnerability.
CVE-2006-3230 allows attackers to inject arbitrary web scripts or HTML, potentially leading to session hijacking or defacement.
CVE-2006-3230 affects Azureus Tracker versions 2.2.0.2, 2.3.0.6, and 2.4.0.2.
Users and administrators of vulnerable versions of Azureus Tracker are at risk of XSS attacks through the search parameter.