CVE-2006-6845: XSS
Published Dec 31, 2006
·Updated
Cross-site scripting (XSS) vulnerability in index.php in CMS Made Simple 1.0.2 allows remote attackers to inject arbitrary web script or HTML via the cntnt01searchinput parameter in a Search action.
Affected Software
1 affected component
CMSmadesimple CMS Made Simple=1.0.2
Event History
Dec 31, 2006
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
DescriptionSeverityAffected Software
Jan 3, 2007
CVE Published
via MITRE·07:00 AM
Data Sourced
via MITRE·07:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-6845?
CVE-2006-6845 is categorized as a medium severity vulnerability due to its potential impact on security through cross-site scripting.
2
How do I fix CVE-2006-6845?
To mitigate CVE-2006-6845, it's recommended to upgrade to a later version of CMS Made Simple that does not contain this vulnerability.
3
Who is affected by CVE-2006-6845?
CVE-2006-6845 affects users of CMS Made Simple version 1.0.2.
4
What type of vulnerability is CVE-2006-6845?
CVE-2006-6845 is a cross-site scripting (XSS) vulnerability.
5
What can attackers do with CVE-2006-6845?
Attackers exploiting CVE-2006-6845 can inject arbitrary web script or HTML into the application, potentially leading to session hijacking or defacement.