ID

VAR-200609-0346


CVE

CVE-2006-5090


TITLE

Phoenix Evolution CMS Multiple Cross-Site Scripting Vulnerabilities

Trust: 1.5

sources: CNVD: CNVD-2006-7556 // BID: 20212 // CNNVD: CNNVD-200609-541

DESCRIPTION

Multiple cross-site scripting (XSS) vulnerabilities in Phoenix Evolution CMS (PECMS) allow remote attackers to inject arbitrary web script or HTML via the (1) mod or (2) action parameters in index.php, or the (3) pageid parameter in modules/pageedit/index.php. NOTE: the provenance of this information is unknown; the details are obtained from third party information. (1) index.php To mod Parameters (2) index.php To action Parameters (3) modules/pageedit/index.php To pageid Parameters. An attacker may leverage these issues to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may let the attacker steal cookie-based authentication credentials and launch other attacks

Trust: 2.61

sources: NVD: CVE-2006-5090 // JVNDB: JVNDB-2006-002197 // CNVD: CNVD-2006-7556 // BID: 20212 // IVD: f7720e74-2353-11e6-abef-000c29c66e3d

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.8

sources: IVD: f7720e74-2353-11e6-abef-000c29c66e3d // CNVD: CNVD-2006-7556

AFFECTED PRODUCTS

vendor:phoenix evolutionmodel:cmsscope: - version: -

Trust: 1.4

vendor:phoenix evolutionmodel:cmsscope:eqversion:*

Trust: 1.0

vendor:nomodel: - scope: - version: -

Trust: 0.6

vendor:phoenixmodel:evolution phoenix evolution cmsscope:eqversion:0

Trust: 0.3

vendor:phoenix evolution cmsmodel: - scope:eqversion:*

Trust: 0.2

sources: IVD: f7720e74-2353-11e6-abef-000c29c66e3d // CNVD: CNVD-2006-7556 // BID: 20212 // JVNDB: JVNDB-2006-002197 // CNNVD: CNNVD-200609-541 // NVD: CVE-2006-5090

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2006-5090
value: MEDIUM

Trust: 1.0

NVD: CVE-2006-5090
value: MEDIUM

Trust: 0.8

CNVD: CNVD-2006-7556
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-200609-541
value: MEDIUM

Trust: 0.6

IVD: f7720e74-2353-11e6-abef-000c29c66e3d
value: MEDIUM

Trust: 0.2

nvd@nist.gov: CVE-2006-5090
severity: MEDIUM
baseScore: 6.8
vectorString: AV:N/AC:M/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 8.6
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2006-7556
severity: MEDIUM
baseScore: 6.8
vectorString: AV:N/AC:M/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 8.6
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

IVD: f7720e74-2353-11e6-abef-000c29c66e3d
severity: MEDIUM
baseScore: 6.8
vectorString: AV:N/AC:M/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 8.6
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.9 [IVD]

Trust: 0.2

sources: IVD: f7720e74-2353-11e6-abef-000c29c66e3d // CNVD: CNVD-2006-7556 // JVNDB: JVNDB-2006-002197 // CNNVD: CNNVD-200609-541 // NVD: CVE-2006-5090

PROBLEMTYPE DATA

problemtype:NVD-CWE-Other

Trust: 1.0

sources: NVD: CVE-2006-5090

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-200609-541

TYPE

XSS

Trust: 0.6

sources: CNNVD: CNNVD-200609-541

CONFIGURATIONS

sources: JVNDB: JVNDB-2006-002197

PATCH

title:Phoenix Evolution CMSurl:http://sourceforge.net/projects/pevolution/

Trust: 0.8

sources: JVNDB: JVNDB-2006-002197

EXTERNAL IDS

db:NVDid:CVE-2006-5090

Trust: 3.2

db:BIDid:20212

Trust: 2.5

db:OSVDBid:33677

Trust: 1.6

db:OSVDBid:33676

Trust: 1.6

db:CNVDid:CNVD-2006-7556

Trust: 0.8

db:CNNVDid:CNNVD-200609-541

Trust: 0.8

db:JVNDBid:JVNDB-2006-002197

Trust: 0.8

db:IVDid:F7720E74-2353-11E6-ABEF-000C29C66E3D

Trust: 0.2

sources: IVD: f7720e74-2353-11e6-abef-000c29c66e3d // CNVD: CNVD-2006-7556 // BID: 20212 // JVNDB: JVNDB-2006-002197 // CNNVD: CNNVD-200609-541 // NVD: CVE-2006-5090

REFERENCES

url:http://www.securityfocus.com/bid/20212

Trust: 2.2

url:http://osvdb.org/33677

Trust: 1.6

url:http://osvdb.org/33676

Trust: 1.6

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2006-5090

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2006-5090

Trust: 0.8

url:http://sourceforge.net/projects/pevolution/

Trust: 0.3

sources: CNVD: CNVD-2006-7556 // BID: 20212 // JVNDB: JVNDB-2006-002197 // CNNVD: CNNVD-200609-541 // NVD: CVE-2006-5090

CREDITS

Root3r_H3ll is credited with the discovery of these vulnerabilities.

Trust: 0.9

sources: BID: 20212 // CNNVD: CNNVD-200609-541

SOURCES

db:IVDid:f7720e74-2353-11e6-abef-000c29c66e3d
db:CNVDid:CNVD-2006-7556
db:BIDid:20212
db:JVNDBid:JVNDB-2006-002197
db:CNNVDid:CNNVD-200609-541
db:NVDid:CVE-2006-5090

LAST UPDATE DATE

2024-08-14T14:53:30.534000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2006-7556date:2006-09-29T00:00:00
db:BIDid:20212date:2006-09-27T17:56:00
db:JVNDBid:JVNDB-2006-002197date:2012-09-25T00:00:00
db:CNNVDid:CNNVD-200609-541date:2006-10-09T00:00:00
db:NVDid:CVE-2006-5090date:2008-11-15T06:29:57.377

SOURCES RELEASE DATE

db:IVDid:f7720e74-2353-11e6-abef-000c29c66e3ddate:2006-09-29T00:00:00
db:CNVDid:CNVD-2006-7556date:2006-09-29T00:00:00
db:BIDid:20212date:2006-09-26T00:00:00
db:JVNDBid:JVNDB-2006-002197date:2012-09-25T00:00:00
db:CNNVDid:CNNVD-200609-541date:2006-09-29T00:00:00
db:NVDid:CVE-2006-5090date:2006-09-29T20:07:00