CVE-2006-5321: XSS
Published Oct 17, 2006
·Updated
Multiple cross-site scripting (XSS) vulnerabilities in phplist before 2.10.3 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
13 affected components
Tincan Phplist=2.8.2
Tincan Phplist=2.6.3
Tincan Phplist=2.6.5
Tincan Phplist=2.6
Tincan Phplist=2.8.12
Tincan Phplist=2.6.2
Tincan Phplist=2.6.4
Tincan Phplist=2.8.7
Tincan Phplist=2.10.1
Tincan Phplist=2.6.1
Tincan Phplist<=2.10.2
Tincan Phplist=2.7.1
Tincan Phplist=2.7.2
Event History
Oct 17, 2006
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Data Sourced
via NVD·05:07 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2006-5321?
CVE-2006-5321 is classified as a vulnerability that can lead to significant risks due to multiple cross-site scripting (XSS) issues.
2
How do I fix CVE-2006-5321?
To fix CVE-2006-5321, upgrade your PHPList installation to version 2.10.3 or later.
3
What systems are affected by CVE-2006-5321?
CVE-2006-5321 affects multiple versions of PHPList, including versions 2.6.x, 2.7.x, 2.8.x, and 2.10.2 and earlier.
4
What type of attack does CVE-2006-5321 facilitate?
CVE-2006-5321 allows remote attackers to execute arbitrary web scripts or HTML through cross-site scripting (XSS) attacks.
5
Is there a workaround for CVE-2006-5321 if I can't upgrade?
If unable to upgrade for CVE-2006-5321, implement input validation and output encoding to mitigate XSS risks.