CVE Database
/

CVE-2006-3312

Back to search

CVE-2006-3312

Published: Jun 29, 2006

Modified: Aug 7, 2024

PUBLISHED

Description

Multiple cross-site scripting (XSS) vulnerabilities in ashmans and Bill Echlin QaTraq 6.5 RC and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) link_print, (2) link_upgrade, (3) link_sql, (4) link_next, (5) link_prev, and (6) link_list parameters in top.inc as included by queries_view_search.php; the (7) msg, (8) component_name, and (9) component_desc parameters in (a) components_copy_content.php, (b) components_modify_content.php, and (c) components_new_content.php; the (10) title, (11) version, and (12) content parameters in design_copy_content.php; the (13) plan_title and (14) plan_content parameters in design_copy_plan_search.php; the (15) title, (16) minor_version, (17) new_version, and (18) content parameters in design_modify_content.php; the (19) title, (20) version, and (21) content parameters in design_new_content.php; the (22) plan_name and (23) plan_desc parameters in design_new_search.php; the (24) file_name parameter in download.php; the (25) username and (26) password parameters in login.php; the (27) title, (28) version, and (29) content parameters in phase_copy_content.php; the (30) content parameter in phase_delete_search.php; the (31) title, (32) minor_version, (33) new_version, and (34) content parameters in phase_modify_content.php; the (35) content, (36) title, (37) version, and (38) content parameters in phase_modify_search.php; the (39) content parameter in phase_view_search.php; the (40) msg, (41) product_name, and (42) product_desc parameters in products_copy_content.php; and possibly the (43) product_name and (44) product_desc parameters in (d) products_copy_search.php, and a large number of additional parameters and executables. NOTE: the vendor notified CVE via e-mail that this issue has been fixed in the 6.8 RC release.

VendorProductVersions

n/a

n/a

affected
n/a

References

27603
vdb-entry
x_refsource_OSVDB
27611
vdb-entry
x_refsource_OSVDB
27614
vdb-entry
x_refsource_OSVDB
27602
vdb-entry
x_refsource_OSVDB
27610
vdb-entry
x_refsource_OSVDB
1016381
vdb-entry
x_refsource_SECTRACK
27612
vdb-entry
x_refsource_OSVDB
27607
vdb-entry
x_refsource_OSVDB
27606
vdb-entry
x_refsource_OSVDB
18620
vdb-entry
x_refsource_BID
27609
vdb-entry
x_refsource_OSVDB
27608
vdb-entry
x_refsource_OSVDB
27599
vdb-entry
x_refsource_OSVDB
27613
vdb-entry
x_refsource_OSVDB
27615
vdb-entry
x_refsource_OSVDB
27605
vdb-entry
x_refsource_OSVDB
1169
third-party-advisory
x_refsource_SREASON
27616
vdb-entry
x_refsource_OSVDB
qatraq-multiple-xss(27355)
vdb-entry
x_refsource_XF
27600
vdb-entry
x_refsource_OSVDB
27601
vdb-entry
x_refsource_OSVDB
27604
vdb-entry
x_refsource_OSVDB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now