CVE-2006-6589: XSS
Cross-site scripting (XSS) vulnerability in ecommerce/control/keywordsearch in the Apache Open For Business Project (OFBiz) and Opentaps 0.9.3 allows remote attackers to inject arbitrary web script or HTML via the SEARCHSTRING parameter, a different issue than CVE-2006-6587. NOTE: some of these details are obtained from third party information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-6589?
CVE-2006-6589 is classified as a cross-site scripting (XSS) vulnerability.
How do I fix CVE-2006-6589?
To fix CVE-2006-6589, ensure proper sanitization and validation of the SEARCH_STRING parameter in your application.
Which versions are affected by CVE-2006-6589?
CVE-2006-6589 affects Apache Open For Business Project (OFBiz) and Opentaps version 0.9.3.
Can CVE-2006-6589 be exploited remotely?
Yes, remote attackers can exploit CVE-2006-6589 to inject arbitrary web scripts or HTML.
Is CVE-2006-6589 different from CVE-2006-6587?
Yes, CVE-2006-6589 describes a different issue compared to CVE-2006-6587.