Vulnerability CVE-2006-1980


Published: 2006-04-21   Modified: 2012-02-12

Description:
Cross-site scripting (XSS) vulnerability in W2B Online Banking allows remote attackers to inject arbitrary web script or HTML via the (1) query string, (2) SID parameter, or (3) ilang parameter.

CVSS2 => (AV:N/AC:H/Au:N/C:N/I:P/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
2.6/10
2.9/10
4.9/10
Exploit range
Attack complexity
Authentication
Remote
High
No required
Confidentiality impact
Integrity impact
Availability impact
None
Partial
None
Affected software
W2B -> Online banking 

 References:
http://xforce.iss.net/xforce/xfdb/25947
http://www.vupen.com/english/advisories/2006/1445
http://www.securityfocus.com/bid/17626
http://www.osvdb.org/24759
http://secunia.com/advisories/19717
http://pridels0.blogspot.com/2006/04/w2b-online-banking-vuln.html

Copyright 2024, cxsecurity.com

 

Back to Top