CVE-2006-1854
| Summary |
Multiple cross-site scripting (XSS) vulnerabilities in BluePay Manager 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML during a login action via the (1) Account Name and (2) Username field. NOTE: the vendor has disputed this vulnerability, saying that "it does not exist currently in the Bluepay 2.0 product," and older versions might not have been affected either. As of 20060512, CVE has not formally investigated this dispute
|
| Publication Date |
April 20, 2006, 1:06 a.m. |
| Registration Date |
Jan. 29, 2021, 3:35 p.m. |
| Last Update |
Aug. 8, 2024, 3:15 a.m. |
|
CVSS2.0 : LOW
|
| Score |
2.6
|
| Vector |
AV:N/AC:H/Au:N/C:N/I:P/A:N |
| 攻撃元区分(AV) |
ネットワーク |
| 攻撃条件の複雑さ(AC) |
高 |
| 攻撃前の認証要否(Au) |
不要 |
| 機密性への影響(C) |
なし |
| 完全性への影響(I) |
低 |
| 可用性への影響(A) |
なし |
| Get all privileges. |
いいえ
|
| Get user privileges |
いいえ
|
| Get other privileges |
いいえ
|
| User operation required |
はい
|
Affected software configurations
| Configuration1 |
or higher |
or less |
more than |
less than |
| cpe:2.3:a:bluepay:bluepay_manager:*:*:*:*:*:*:*:* |
|
2.0 |
|
|
Related information, measures and tools
Common Vulnerabilities List