CVE-2006-2648
Published May 30, 2006
Last updated 6 years ago
Overview
- Description
- Cross-site scripting (XSS) vulnerability in perform_search.asp for ASPBB 0.52 and earlier allows remote attackers to inject arbitrary HTML or web script via the search parameter.
- Source
- cve@mitre.org
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 2.6
- Impact score
- 2.9
- Exploitability score
- 4.9
- Vector string
- AV:N/AC:H/Au:N/C:N/I:P/A:N
Weaknesses
- nvd@nist.gov
- NVD-CWE-Other
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:aspbb:aspbb:0.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BC95BB77-F425-44A8-A958-77070744648A" }, { "criteria": "cpe:2.3:a:aspbb:aspbb:0.1.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "22935EE2-7E21-43E1-9E01-0D8779371A2F" }, { "criteria": "cpe:2.3:a:aspbb:aspbb:0.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "05A0D865-9EFD-4103-A43D-DAC89AF5F9B1" }, { "criteria": "cpe:2.3:a:aspbb:aspbb:0.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C6CD4938-A7B3-450E-AC8F-08648C41A3D1" }, { "criteria": "cpe:2.3:a:aspbb:aspbb:0.3.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A596800C-B18A-4FC3-88F3-87C125E5275C" }, { "criteria": "cpe:2.3:a:aspbb:aspbb:0.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "64592E8F-2FB8-40BE-B0D0-80A7DBCB7708" }, { "criteria": "cpe:2.3:a:aspbb:aspbb:0.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2769B12B-42A7-4019-9F70-167061EF74E7" }, { "criteria": "cpe:2.3:a:aspbb:aspbb:0.5.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "869C1D84-2493-4634-8FB9-0F154CD700E5" }, { "criteria": "cpe:2.3:a:aspbb:aspbb:0.5.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6EC94A3E-5F1F-4F64-B711-C052AA97B97F" }, { "criteria": "cpe:2.3:a:aspbb:aspbb:alpha1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8E8CDC73-D39A-47E4-B2F9-6A94A2DAE9EC" } ], "operator": "OR" } ] } ]