CVE-2006-4528
Summary
| CVE | CVE-2006-4528 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-09-01 23:04:00 UTC |
| Updated | 2018-10-17 21:37:00 UTC |
| Description | Multiple cross-site scripting (XSS) vulnerabilities in membrepass 1.5 allow remote attackers to inject arbitrary web script or HTML via the (1) recherche parameter in recherchemembre.php and the (2) email parameter in test.php. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Membrepass | Membrepass | 1.5 | All | All | All |
| Application | Membrepass | Membrepass | 1.5 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Membrepass Multiple Cross-Site Scripting Vulnerabilities | BID | www.securityfocus.com | |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| Membrepass v1.5 Php code execution, Xss, Sql Injection - CXSecurity.com | SREASON | securityreason.com | |
| new.fr is available for purchase - Sedo.com | MISC | acid-root.new.fr | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| Membrepass Multiple Vulnerabilities - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.