Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Linux_Root

#30380of 53,608
8.6Total CVSS
Vulnerabilities · 2
Medium
2
PT-2006-3421
4.3
2006-05-19
Openwiki · Openwiki · CVE-2006-2473
**Name of the Vulnerable Software and Affected Versions** OpenWiki version 0.78 **Description** A cross-site scripting (XSS) issue allows remote attackers to inject arbitrary web script or HTML via the `p` parameter in the ow.asp file. This issue has been disputed by the vendor, who claims that code injection is not possible due to escaping of URL parameters and wikipage content. **Recommendations** For OpenWiki version 0.78, consider restricting access to the ow.asp file or the `p` parameter to minimize the risk of exploitation, as a temporary workaround until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2006-3432
4.3
2006-05-19
Icewarp · Icewarp Web Mail · CVE-2006-2484
**Name of the Vulnerable Software and Affected Versions** IceWarp WebMail versions 5.5.1 and earlier **Description** A cross-site scripting (XSS) issue exists, allowing remote attackers to inject arbitrary web script or HTML via the `PHPSESSID` parameter. **Recommendations** For IceWarp WebMail versions 5.5.1 and earlier, update to a version later than 5.5.1 to resolve the issue.