CVE-2006-5294: XSS
Published Oct 16, 2006
·Updated
Cross-site scripting (XSS) vulnerability in index.php in phplist before 2.10.3 allows remote attackers to inject arbitrary web script or HTML via the unsubscribeemail parameter.
Affected Software
8 affected components
Tincan Phplist<=2.10.2
Tincan Phplist=2.6
Tincan Phplist=2.6.1
Tincan Phplist=2.6.2
Tincan Phplist=2.6.3
Tincan Phplist=2.6.4
Tincan Phplist=2.8.12
Tincan Phplist=2.10.1
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Oct 16, 2006
CVE Published
06:07 PM
Data Sourced
via NVD·06:07 PM
RemedyDescriptionSeverityAffected Software
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-5294?
CVE-2006-5294 is classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2006-5294?
To fix CVE-2006-5294, upgrade to PHPList version 2.10.3 or later to eliminate the XSS vulnerability.
3
What software is affected by CVE-2006-5294?
CVE-2006-5294 affects PHPList versions prior to 2.10.3, specifically versions 2.6 through 2.10.2.
4
What is the impact of CVE-2006-5294?
The impact of CVE-2006-5294 allows attackers to inject malicious scripts into webpages viewed by users.
5
How can I identify if I am vulnerable to CVE-2006-5294?
You can identify if you are vulnerable to CVE-2006-5294 by checking your PHPList version against the affected versions listed.