6.8
CVSSv2

CVE-2006-2699

Published: 31/05/2006 Updated: 18/10/2018
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in getimage.php in Geeklog 1.4.0sr2 and previous versions allows remote malicious users to inject arbitrary HTML or web script via the image argument in a show action.

Vulnerable Product Search on Vulmon Subscribe to Product

geeklog geeklog 1.3.5

geeklog geeklog 1.3.10 rc3

geeklog geeklog 1.4.0 sr1

geeklog geeklog 1.3.8

geeklog geeklog 1.3.9 sr2

geeklog geeklog 1.3.10 rc2

geeklog geeklog 1.3.6

geeklog geeklog 1.4.0 beta1

geeklog geeklog 1.3.9 sr4

geeklog geeklog 1.3.11 sr3

geeklog geeklog 1.3.9 rc3

geeklog geeklog 1.3.7 sr2

geeklog geeklog 1.3.11 sr2

geeklog geeklog 1.3.7 sr5

geeklog geeklog 1.3.8 1 sr5

geeklog geeklog 1.3.7

geeklog geeklog 1.35

geeklog geeklog 1.3.9 rc1

geeklog geeklog 1.3.10

geeklog geeklog 1.3.8 1 sr2

geeklog geeklog 1.3.8 1 sr6

geeklog geeklog 1.3.8 1 sr1

geeklog geeklog 1.4.0 sr2

geeklog geeklog 1.3.8 1 sr3

geeklog geeklog 1.3.11 rc1

geeklog geeklog 1.3

geeklog geeklog 1.3.7 sr3

geeklog geeklog 1.3.8 1 sr4

geeklog geeklog 1.4.0

geeklog geeklog 1.3.9 sr1

geeklog geeklog 1.3.11 sr1

geeklog geeklog 1.3.9

geeklog geeklog 1.3.7 sr1

geeklog geeklog 1.3.5 sr1

geeklog geeklog 1.3.9 rc2

geeklog geeklog 1.3.9 sr3

geeklog geeklog 1.3.11 sr4

geeklog geeklog 1.3.11

geeklog geeklog 1.3.8 1

geeklog geeklog 1.3.10 rc1

geeklog geeklog 1.3.7 sr4

Exploits

source: wwwsecurityfocuscom/bid/18154/info Geeklog is prone to multiple input-validation vulnerabilities The issues include cross-site scripting and SQL-injection vulnerabilities These issues are due to a failure in the application to properly sanitize user-supplied input A successful exploit of these vulnerabilities could allow an a ...