Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2006-5830

Multiple cross-site scripting (XSS) vulnerabilities in All In One Control Panel (AIOCP) 1.3.007 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) topid, (2) forid, and (3) catid parameters to code/cp_forum_view.php; (4) choosed_language parameter to cp_dpage.php; (5) orderdir parameter to cp_links_search.php; (6) order_field parameter to (a) cp_show_ec_products.php and (b) cp_users_online.php; and the (7) signature and (8) fiscal code fields in the user profile.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.022
EPSS Ranking 83.6%
CVSS Severity
CVSS v2 Score 6.8
References
Products affected by CVE-2006-5830
  • Aiocp » Aiocp » Version: 1.3.000
    cpe:2.3:a:aiocp:aiocp:1.3.000
  • Aiocp » Aiocp » Version: 1.3.001
    cpe:2.3:a:aiocp:aiocp:1.3.001
  • Aiocp » Aiocp » Version: 1.3.002
    cpe:2.3:a:aiocp:aiocp:1.3.002
  • Aiocp » Aiocp » Version: 1.3.003
    cpe:2.3:a:aiocp:aiocp:1.3.003
  • Aiocp » Aiocp » Version: 1.3.004
    cpe:2.3:a:aiocp:aiocp:1.3.004
  • Aiocp » Aiocp » Version: 1.3.005
    cpe:2.3:a:aiocp:aiocp:1.3.005
  • Aiocp » Aiocp » Version: 1.3.006
    cpe:2.3:a:aiocp:aiocp:1.3.006
  • Aiocp » Aiocp » Version: 1.3.007
    cpe:2.3:a:aiocp:aiocp:1.3.007


Contact Us

Shodan ® - All rights reserved