Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2006-0894

Multiple cross-site scripting (XSS) vulnerabilities in NOCC Webmail 1.0 allow remote attackers to inject arbitrary web script or HTML via (1) the html_error_occurred parameter in error.php, (2) html_filter_select parameter in filter_prefs.php, (3) html_no_mail parameter in no_mail.php, the (4) page_line, (5) prev, and (6) next parameters in html_bottom_table.php, and the (7) _SESSION['nocc_theme'] parameter in footer.php.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.01
EPSS Ranking 75.6%
CVSS Severity
CVSS v2 Score 4.3
Products affected by CVE-2006-0894
  • Nocc » Nocc » Version: 1.0
    cpe:2.3:a:nocc:nocc:1.0


Contact Us

Shodan ® - All rights reserved