« Volver al listado

CVE-2006-5430

Estado: ModificadaMedia (6.8)—

Vulnerabilida de secuencias de comandos en sitios cruzados en la funcionalidad de búsqueda en db-central (dbc) Enterprise CMS y db-central CMS permite a un atacante remoto inyectar secuencias de comandos web o HTML a través del parámetro needle. NOTA: el origen de esta información es desconocido; los detalles se obtuvieron de información de terceros.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2006-5430",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.8,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": true,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2006-10-20T17:07:00.000",
  "references": [
    {
      "url": "http://secunia.com/advisories/22407",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.osvdb.org/29832",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/20622",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2006/4106",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/29666",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/22407",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.osvdb.org/29832",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/20622",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2006/4106",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/29666",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Cross-site scripting (XSS) vulnerability in the search functionality in db-central (dbc) Enterprise CMS and db-central CMS allows remote attackers to inject arbitrary web script or HTML via the needle parameter.  NOTE: the provenance of this information is unknown; the details are obtained from third party information."
    },
    {
      "lang": "es",
      "value": "Vulnerabilida de secuencias de comandos en sitios cruzados en la funcionalidad de búsqueda en db-central (dbc) Enterprise CMS y db-central CMS permite a un atacante remoto inyectar secuencias de comandos web o HTML a través del parámetro needle. NOTA: el origen de esta información es desconocido; los detalles se obtuvieron de información de terceros."
    }
  ],
  "lastModified": "2026-06-16T22:31:10.983",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:db-central:cms:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "22A12AE3-F432-4F16-84D5-9A0773060E4C"
            },
            {
              "criteria": "cpe:2.3:a:db-central:enterprise_cms:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DA43725D-0762-493A-885D-97C7E03DBA42"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}