CVE-2006-6509 - CERT CVE
ID CVE-2006-6509
Sažetak Cross-site scripting (XSS) vulnerability in the skinning feature in SiteKiosk before 6.5.150 allows local users to bypass security protections and inject arbitrary web script or HTML via an ABOUT: URI, which is displayed in the title bar of the browser.
Reference
CVSS
Base: 4.1
Impact: 6.4
Exploitability:2.7
Pristup
VektorSloženostAutentikacija
LOCAL MEDIUM SINGLE
Impact
PovjerljivostCjelovitostDostupnost
PARTIAL PARTIAL PARTIAL
CVSS vektor AV:L/AC:M/Au:S/C:P/I:P/A:P
Zadnje važnije ažuriranje 17-10-2018 - 21:49
Objavljeno 14-12-2006 - 00:28