6.8
CVSSv2

CVE-2006-3052

Published: 16/06/2006 Updated: 08/03/2011
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in Event Registration allows remote malicious users to inject arbitrary web script or HTML via the (1) event_id parameter to view-event-details.php or (2) select_events parameter to event-registration.php. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

Vulnerable Product Search on Vulmon Subscribe to Product

cescripts event registration 2checkout

cescripts event registration corporate

cescripts event registration paypal

cescripts event registration rsvp 1.0

Exploits

source: wwwsecurityfocuscom/bid/18402/info CEScripts scripts are prone to multiple cross-site scripting vulnerabilities because they fail to properly sanitize user-supplied input An attacker may leverage these issues to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site This ma ...