Vulnerability Details CVE-2006-4442
Cross-site scripting (XSS) vulnerability in PHP iAddressBook before 0.95 allows remote attackers to inject arbitrary web script or HTML via the cat_name parameter, related to adding a category. (categories field). NOTE: some details are obtained from third party information.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.012
EPSS Ranking 78.0%
CVSS Severity
CVSS v2 Score 6.8
Products affected by CVE-2006-4442
-
cpe:2.3:a:clemens_wacha:php_iaddressbook:0.9
-
cpe:2.3:a:clemens_wacha:php_iaddressbook:0.91
-
cpe:2.3:a:clemens_wacha:php_iaddressbook:0.91a
-
cpe:2.3:a:clemens_wacha:php_iaddressbook:0.92
-
cpe:2.3:a:clemens_wacha:php_iaddressbook:0.93
-
cpe:2.3:a:clemens_wacha:php_iaddressbook:0.94