CVE-2006-1900 - CERT CVE
ID CVE-2006-1900
Sažetak Multiple buffer overflows in World Wide Web Consortium (W3C) Amaya 9.4, and possibly other versions including 8.x before 8.8.5, allow remote attackers to execute arbitrary code via a long value in (1) the COMPACT attribute of the COLGROUP element, (2) the ROWS attribute of the TEXTAREA element, and (3) the COLOR attribute of the LEGEND element; and via other unspecified attack vectors consisting of "dozens of possible snippets."
Reference
CVSS
Base: 7.6
Impact: 10.0
Exploitability:4.9
Pristup
VektorSloženostAutentikacija
NETWORK HIGH NONE
Impact
PovjerljivostCjelovitostDostupnost
COMPLETE COMPLETE COMPLETE
CVSS vektor AV:N/AC:H/Au:N/C:C/I:C/A:C
Zadnje važnije ažuriranje 18-10-2018 - 16:37
Objavljeno 20-04-2006 - 10:02