CVE-2006-5524: XSS
Published Oct 26, 2006
·Updated
Cross-site scripting (XSS) vulnerability in index.php in phplist 2.10.2 allows remote attackers to inject arbitrary web script or HTML via the p parameter. NOTE: This issue might overlap CVE-2006-5321.
Affected Software
1 affected component
PHPlist PHPList=2.10.2
Event History
Oct 26, 2006
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Data Sourced
via NVD·04:07 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2006-5524?
The severity of CVE-2006-5524 is generally classified as medium due to its potential for enabling cross-site scripting attacks.
2
How do I fix CVE-2006-5524?
To fix CVE-2006-5524, it is recommended to upgrade phpList to a version that patches this vulnerability.
3
What systems are affected by CVE-2006-5524?
CVE-2006-5524 specifically affects phpList version 2.10.2.
4
What type of vulnerability is CVE-2006-5524?
CVE-2006-5524 is classified as a cross-site scripting (XSS) vulnerability.
5
Can CVE-2006-5524 be exploited remotely?
Yes, CVE-2006-5524 can be exploited remotely, allowing attackers to inject arbitrary web scripts or HTML.