CVE-2006-6174
Summary
| CVE | CVE-2006-6174 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-11-30 16:28:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Cross-site scripting (XSS) vulnerability in tDiary before 2.0.3 and 2.1.x before 2.1.4.20061126 allows remote attackers to inject arbitrary web script or HTML via the conf parameter in (1) tdiary.rb and (2) skel/conf.rhtml. |
Risk And Classification
Primary CVSS: v2.0 4.3 from [email protected]
AV:N/AC:M/Au:N/C:N/I:P/A:N
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.tdiary.org/download/tdiary.20061126.patch | af854a3a-2127-422b-91ae-364da2661108 | www.tdiary.org | |
| TDiary Conf Parameter Cross-Site Scripting Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| tDiary.org - tDiaryの脆弱性に関する報告(2006-11-26) | af854a3a-2127-422b-91ae-364da2661108 | www.tdiary.org | |
| www.osvdb.org/31993 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | |
| JVN#47223461: tDiary におけるクロスサイトスクリプティングの脆弱性 | af854a3a-2127-422b-91ae-364da2661108 | jvn.jp | |
| Page not found - SourceForge.net | af854a3a-2127-422b-91ae-364da2661108 | sourceforge.net | Patch |
| tDiary "conf" Cross-Site Scripting Vulnerability - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| www.osvdb.org/30701 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | |
| JVN:JVN#47223461 | MITRE | jvn.jp | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.