Scriptme products BBCode 'url' XSS Vulnerability

Risk: Low
Local: No
Remote: Yes

CVSS Base Score: 4.3/10
Impact Subscore: 2.9/10
Exploitability Subscore: 8.6/10
Exploit range: Remote
Attack complexity: Medium
Authentication: No required
Confidentiality impact: None
Integrity impact: Partial
Availability impact: None

New eVuln Advisory: Scriptme products BBCode 'url' XSS Vulnerability --------------------Summary---------------- eVuln ID: EV0065 CVE: CVE-2006-0661 Vendor: Scriptme Vendor's Web Site: Software: "SmE GB Host" "SmE Blog Host" Versions: Critical Level: Harmless Type: Cross-Site Scripting Class: Remote Status: Unpatched. No reply from developer(s) Exploit: Not Available Solution: Not Available Discovered by: Aliaksandr Hartsuyeu ( -----------------Description--------------- Arbitrary script code insertion is possible in BBcode [url] tag. "SmE GB Host" 1.21 - vulnerable "SmE Blog Host" - vulnerable --------------Exploit---------------------- Waiting for developer(s) reply. If there is no reply exploitation code will be published in 10 days --------------Solution--------------------- No Patch available. --------------Credit----------------------- Discovered by: Aliaksandr Hartsuyeu ( Regards, Aliaksandr Hartsuyeu - Penetration Testing Services

