CVE-2006-2669
Summary
| CVE | CVE-2006-2669 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-05-30 21:02:00 UTC |
| Updated | 2018-10-18 16:41:00 UTC |
| Description | Multiple cross-site scripting (XSS) vulnerabilities in Pre Shopping Mall 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) search parameter in search.php (the "search box"), (2) the prodid parameter in detail.php, and the (3) cid parameter in products.php. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Preprojects.com | Pre Shopping Mall | 1.0 | All | All | All |
| Application | Preprojects.com | Pre Shopping Mall | 1.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| Pre Shopping Mall Multiple Input Validation Vulnerabilities | BID | www.securityfocus.com | |
| 26081 | OSVDB | www.osvdb.org | |
| 26080 | OSVDB | www.osvdb.org | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | Vendor Advisory |
| Secunia - Advisories - Pre Shopping Mall SQL Injection Vulnerabilities | SECUNIA | secunia.com | Patch, Vendor Advisory |
| SecurityReason - Pre Shopping Mall v1.0 | SREASON | securityreason.com | |
| 26082 | OSVDB | www.osvdb.org | |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.