4.3
CVSSv2

CVE-2006-0857

Published: 23/02/2006 Updated: 18/10/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in Chatbox Plugin 1.0 in e107 0.7.2 allows remote malicious users to inject arbitrary HTML or web script via a Chatbox, as demonstrated using a SCRIPT element.

Vulnerable Product Search on Vulmon Subscribe to Product

e107 chatbox plugin 1.0

e107 e107 0.7.2

Exploits

source: wwwsecurityfocuscom/bid/16719/info The e107 content management system (CMS) Chatbox Plugin is prone to an HTML-injection vulnerability This issue is due to a failure in the application to properly sanitize user-supplied input before using it in dynamically generated content Attacker-supplied HTML and script code would be execu ...