CVE-2006-4754
Summary
| CVE | CVE-2006-4754 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-09-13 22:07:00 UTC |
| Updated | 2017-07-20 01:33:00 UTC |
| Description | Cross-site scripting (XSS) vulnerability in index.php in PHProg before 1.1 allows remote attackers to inject arbitrary web script or HTML via the album parameter, which is used in an opendir call. NOTE: the same primary issue can be used for full path disclosure with an invalid parameter that reveals the installation path in an error message. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Comscripts | Phprog | 1.0 | All | All | All |
| Application | Comscripts | Phprog | 1.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 20060911 PHProg : Local File Inclusion + XSS + Full path | FULLDISC | marc.info | |
| www.comscripts.com/scripts/php.phprog-album-photo-php.2117.html | CONFIRM | www.comscripts.com | Patch |
| www.pconfig.com/cdg393/adviso/PHProg.txt | MISC | www.pconfig.com | Exploit, Vendor Advisory |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| PHProg Multiple Vulnerabilities - Advisories - Secunia | SECUNIA | secunia.com | Exploit, Patch, Vendor Advisory |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| RETIRED: PHProg Multiple Vulnerabilities | BID | www.securityfocus.com | Exploit |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.