2.6
CVSSv2

CVE-2006-3320

Published: 30/06/2006 Updated: 18/10/2018
CVSS v2 Base Score: 2.6 | Impact Score: 2.9 | Exploitability Score: 4.9
VMScore: 231
Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in command.php in SiteBar 3.3.8 and previous versions allows remote malicious users to inject arbitrary web script or HTML via the command parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

sitebar sitebar 3.3.2

sitebar sitebar 3.3.7

sitebar sitebar

sitebar sitebar 3.3.5

sitebar sitebar 3.3.6

sitebar sitebar 3.3.3

sitebar sitebar 3.3.4

Vendor Advisories

A cross-site scripting vulnerability has been discovered in sitebar, a web based bookmark manager written in PHP, which allows remote attackers to inject arbitrary web script or HTML For the stable distribution (sarge) this problem has been fixed in version 326-71 For the unstable distribution (sid) this problem has been fixed in version 338 ...

Exploits

Nth Dimension Security Advisory (NDSA20071016) - The SiteBar application has single high risk issues with its translation module It can can be made to retrieve any file to which the web server user has read access The SiteBar application has multiple high risk issues with its translation module It can be made to execute arbitrary code to gain re ...