4.3
CVSSv2

CVE-2006-0220

Published: 16/01/2006 Updated: 19/10/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in DCP-Portal 5.3 up to and including 6.1.1 allow remote malicious users to inject arbitrary web script or HTML via (1) the day parameter in calendar.php and (2) the input form in search.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. It is possible that this issue is resultant from an SQL injection problem in CVE-2005-4227.3 and CVE-2005-4227.13.

Vulnerable Product Search on Vulmon Subscribe to Product

codeworx technologies dcp-portal 5.3

codeworx technologies dcp-portal 6.1.1

codeworx technologies dcp-portal 5.3.1

codeworx technologies dcp-portal 5.3.2

codeworx technologies dcp-portal 6.0

codeworx technologies dcp-portal 6.1