First published: Mon Jul 31 2006(Updated: )
Cross-site scripting (XSS) vulnerability in Alkacon OpenCms before 6.2.2 allows remote authenticated users to inject arbitrary web script or HTML via the message body.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Alkacon OpenCMS | =6.0.3 | |
Alkacon OpenCMS | =6.0.4 | |
Alkacon OpenCMS | <=6.2.1 | |
Alkacon OpenCMS | =6.0.0 | |
Alkacon OpenCMS | =6.2 | |
Alkacon OpenCMS | =6.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-3933 is considered a medium severity cross-site scripting (XSS) vulnerability.
To fix CVE-2006-3933, you should upgrade to Alkacon OpenCms version 6.2.2 or later.
CVE-2006-3933 affects authenticated users of Alkacon OpenCms versions up to 6.2.1.
CVE-2006-3933 is a cross-site scripting (XSS) vulnerability that allows the injection of arbitrary web scripts.
Attackers can exploit CVE-2006-3933 to inject and execute malicious scripts in the context of the web application.