CVE Database
/

CVE-2006-3089

Back to search

CVE-2006-3089

Published: Jun 19, 2006

Modified: Aug 7, 2024

PUBLISHED

Description

Multiple cross-site scripting (XSS) vulnerabilities in PhpMyFactures 1.0, and possibly 1.2 and earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) prefixe_dossier parameter in (a) /inc/header.php; (2) msg parameter in (b) /remises/ajouter_remise.php, (c) /tva/ajouter_tva.php, (d) /stocks/ajouter.php, (e) /pays/ajouter_pays.php, (f) /produits/ajouter_cat.php, (g) /produits/ajouter_produit.php and (h) /produits/modifier_cat.php; (3) tire parameter in /remises/ajouter_remise.php; (4) quantite, (5) taux and (6) date parameter in /stocks/ajouter.php; and (7) pays and (8) prefixe parameter in /pays/ajouter_pays.php.

VendorProductVersions

n/a

n/a

affected
n/a

References

26482
vdb-entry
x_refsource_OSVDB
26481
vdb-entry
x_refsource_OSVDB
26480
vdb-entry
x_refsource_OSVDB
26479
vdb-entry
x_refsource_OSVDB
26478
vdb-entry
x_refsource_OSVDB
26485
vdb-entry
x_refsource_OSVDB
26483
vdb-entry
x_refsource_OSVDB
20642
third-party-advisory
x_refsource_SECUNIA
1111
third-party-advisory
x_refsource_SREASON
26484
vdb-entry
x_refsource_OSVDB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now