CVE-2006-4964
Summary
| CVE | CVE-2006-4964 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-09-23 10:07:00 UTC |
| Updated | 2011-03-08 02:42:00 UTC |
| Description | Cross-site scripting (XSS) vulnerability in MAXdev MDPro 1.0.76 before 20060918 allows remote attackers to inject arbitrary web script or HTML via (1) vectors that bypass the XSS protection mechanisms of the pnVarCleanFromInput function, and (2) unspecified vectors related to the AntiCracker. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Maxdev | Md-pro | 1.0.72 | All | All | All |
| Application | Maxdev | Md-pro | 1.0.73 | All | All | All |
| Application | Maxdev | Md-pro | 1.0.75 | All | All | All |
| Application | Maxdev | Md-pro | 1.0.72 | All | All | All |
| Application | Maxdev | Md-pro | 1.0.73 | All | All | All |
| Application | Maxdev | Md-pro | 1.0.75 | All | All | All |
| Application | Maxdev | Md-pro | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| JVN#46630603: MDPro におけるクロスサイトスクリプティングの脆弱性 | JVN | jvn.jp | |
| MAXdev MD-Pro Cross-Site Scripting Vulnerability - Advisories - Secunia | SECUNIA | secunia.com | Patch, Vendor Advisory |
| MAXdev :: MDPro, the most easy to use and feature rich GPL Content Management System. | CONFIRM | www.maxdev.com | Patch |
| Security fixes for MDPro 1.0.76 :: MAXdev :: MDPro, the most easy to use and feature rich GPL Content Management System. | CONFIRM | www.maxdev.com | Patch |
| MAXdev MD-Pro PnVarCleanFromInput Cross-Site Scripting Vulnerability | BID | www.securityfocus.com | Patch |
| JVN:JVN#46630603 | MITRE | jvn.jp | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.