CVE Database
/

CVE-2006-1120

Back to search

CVE-2006-1120

Published: Mar 9, 2006

Modified: Aug 7, 2024

PUBLISHED

Description

Multiple cross-site scripting (XSS) vulnerabilities in DCP-Portal 6.1.1 and earlier, with register_globals enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) its_url parameter in the documents page and (2) url parameter in the send_write page of (a) index.php; (3) subject, and (4) images parameters to (b) calendar.php; (5) bid, (6) replying_msg, (7) subject, (8) body, and (9) mid parameters to (c) forums.php; (10) subject and (11) message parameters to (d) inbox.php; (12) subject_color and (13) email parameters to (e) lostpassword.php; and the (14) c_name, (15) content_inicial, and (16) cid parameters to (f) mycontents.php. NOTE: the calendar.php/day vector is already subsumed by CVE-2006-0220, and the calendar.php/month, calendar.php/year, and search.php/q parameters for calendar.php are already subsumed by CVE-2004-2511.

VendorProductVersions

n/a

n/a

affected
n/a

References

23979
vdb-entry
x_refsource_OSVDB
23981
vdb-entry
x_refsource_OSVDB
23980
vdb-entry
x_refsource_OSVDB
17050
vdb-entry
x_refsource_BID
392
third-party-advisory
x_refsource_SREASON
23978
vdb-entry
x_refsource_OSVDB
23976
vdb-entry
x_refsource_OSVDB
23977
vdb-entry
x_refsource_OSVDB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now