CVE-2006-5190 (CNNVD-200610-114)

MEDIUM 有利用代码
中文标题:
osCommerce多个跨站脚本攻击漏洞
英文标题:
Multiple cross-site scripting (XSS) vulnerabilities in osCommerce 2.2 Milestone 2 Update 060817 allo...
CVSS分数: 4.3
发布时间: 2006-10-06 19:00:00
漏洞类型: 跨站脚本
状态: PUBLISHED
数据质量分数: 0.40
数据版本: v20
漏洞描述
中文描述:

osCommerce 2.2 Milestone 2 Update 060817中的多个跨站脚本攻击漏洞,远程攻击者可以通过(1)在(a)banner_manager.php,(b)banner_statistics.php,(c)countries.php,(d)currencies.php,(e)languages.php,(f)manufacturers.php,(g)newsletters.php,(h)orders_status.php,(i)products_attributes.php,(j)products_expected.php,(k)reviews.php,(l)specials.php,(m)stats_products_purchased.php,(n)stats_products_viewed.php,(o)tax_classes.php,(p)tax_rates.php或(q)/admin下zones.php脚本中的page参数,以及(2)在(r)admin/geo_zones.php中的zpage参数来注入任意的Web脚本或HTML。

英文描述:

Multiple cross-site scripting (XSS) vulnerabilities in osCommerce 2.2 Milestone 2 Update 060817 allow remote attackers to inject arbitrary web script or HTML via the (1) page parameter in the (a) banner_manager.php, (b) banner_statistics.php, (c) countries.php, (d) currencies.php, (e) languages.php, (f) manufacturers.php, (g) newsletters.php, (h) orders_status.php, (i) products_attributes.php, (j) products_expected.php, (k) reviews.php, (l) specials.php, (m) stats_products_purchased.php, (n) stats_products_viewed.php, (o) tax_classes.php, (p) tax_rates.php, or (q) zones.php scripts in /admin, and the (2) zpage parameter in (r) admin/geo_zones.php.

CWE类型:
(暂无数据)
标签:
webapps php Lostmon OSVDB-29795 OSVDB-29796 OSVDB-29797 OSVDB-29798 OSVDB-29799 OSVDB-29800 OSVDB-29801 OSVDB-29802 OSVDB-29803 OSVDB-29804 OSVDB-29805 OSVDB-29806 OSVDB-29807 OSVDB-29808 OSVDB-29809 OSVDB-29810 OSVDB-29811
受影响产品
厂商 产品 版本 版本范围 平台 CPE
oscommerce oscommerce * - - cpe:2.3:a:oscommerce:oscommerce:*:*:*:*:*:*:*:*
oscommerce oscommerce 1.1 - - cpe:2.3:a:oscommerce:oscommerce:1.1:*:*:*:*:*:*:*
oscommerce oscommerce 1.5.1 - - cpe:2.3:a:oscommerce:oscommerce:1.5.1:*:*:*:*:*:*:*
oscommerce oscommerce 1.11 - - cpe:2.3:a:oscommerce:oscommerce:1.11:*:*:*:*:*:*:*
oscommerce oscommerce 1.12 - - cpe:2.3:a:oscommerce:oscommerce:1.12:*:*:*:*:*:*:*
oscommerce oscommerce 1.13 - - cpe:2.3:a:oscommerce:oscommerce:1.13:*:*:*:*:*:*:*
oscommerce oscommerce 2.1 - - cpe:2.3:a:oscommerce:oscommerce:2.1:*:*:*:*:*:*:*
oscommerce oscommerce 2.2_cvs - - cpe:2.3:a:oscommerce:oscommerce:2.2_cvs:*:*:*:*:*:*:*
oscommerce oscommerce 2.2_ms1 - - cpe:2.3:a:oscommerce:oscommerce:2.2_ms1:*:*:*:*:*:*:*
oscommerce oscommerce 2.2_ms2 - - cpe:2.3:a:oscommerce:oscommerce:2.2_ms2:*:*:*:*:*:*:*
oscommerce oscommerce 2.2_ms3 - - cpe:2.3:a:oscommerce:oscommerce:2.2_ms3:*:*:*:*:*:*:*
解决方案
中文解决方案:
(暂无数据)
英文解决方案:
(暂无数据)
临时解决方案:
(暂无数据)
参考链接
28750 exploit
cve.org
访问
29801 vdb-entry
cve.org
访问
28746 exploit
cve.org
访问
29803 vdb-entry
cve.org
访问
ADV-2006-3917 vdb-entry
cve.org
访问
29798 vdb-entry
cve.org
访问
29808 vdb-entry
cve.org
访问
29807 vdb-entry
cve.org
访问
22275 third-party-advisory
cve.org
访问
29802 vdb-entry
cve.org
访问
29795 vdb-entry
cve.org
访问
28759 exploit
cve.org
访问
28755 exploit
cve.org
访问
无标题 x_refsource_MISC
cve.org
访问
28747 exploit
cve.org
访问
28744 exploit
cve.org
访问
1016979 vdb-entry
cve.org
访问
29809 vdb-entry
cve.org
访问
29799 vdb-entry
cve.org
访问
28757 exploit
cve.org
访问
28748 exploit
cve.org
访问
29810 vdb-entry
cve.org
访问
29811 vdb-entry
cve.org
访问
28758 exploit
cve.org
访问
28753 exploit
cve.org
访问
29797 vdb-entry
cve.org
访问
29806 vdb-entry
cve.org
访问
28749 exploit
cve.org
访问
29800 vdb-entry
cve.org
访问
20343 vdb-entry
cve.org
访问
oscommerce-page-xss(29355) vdb-entry
cve.org
访问
29796 vdb-entry
cve.org
访问
28743 exploit
cve.org
访问
28754 exploit
cve.org
访问
28745 exploit
cve.org
访问
29804 vdb-entry
cve.org
访问
28756 exploit
cve.org
访问
29805 vdb-entry
cve.org
访问
28752 exploit
cve.org
访问
ExploitDB EDB-28743 EXPLOIT
exploitdb
访问
Download Exploit EDB-28743 EXPLOIT
exploitdb
访问
CVE Reference: CVE-2006-5190 ADVISORY
cve.org
访问
ExploitDB EDB-28744 EXPLOIT
exploitdb
访问
Download Exploit EDB-28744 EXPLOIT
exploitdb
访问
ExploitDB EDB-28745 EXPLOIT
exploitdb
访问
Download Exploit EDB-28745 EXPLOIT
exploitdb
访问
ExploitDB EDB-28746 EXPLOIT
exploitdb
访问
Download Exploit EDB-28746 EXPLOIT
exploitdb
访问
ExploitDB EDB-28747 EXPLOIT
exploitdb
访问
Download Exploit EDB-28747 EXPLOIT
exploitdb
访问
ExploitDB EDB-28748 EXPLOIT
exploitdb
访问
Download Exploit EDB-28748 EXPLOIT
exploitdb
访问
ExploitDB EDB-28749 EXPLOIT
exploitdb
访问
Download Exploit EDB-28749 EXPLOIT
exploitdb
访问
ExploitDB EDB-28750 EXPLOIT
exploitdb
访问
Download Exploit EDB-28750 EXPLOIT
exploitdb
访问
ExploitDB EDB-28751 EXPLOIT
exploitdb
访问
Download Exploit EDB-28751 EXPLOIT
exploitdb
访问
ExploitDB EDB-28752 EXPLOIT
exploitdb
访问
Download Exploit EDB-28752 EXPLOIT
exploitdb
访问
ExploitDB EDB-28753 EXPLOIT
exploitdb
访问
Download Exploit EDB-28753 EXPLOIT
exploitdb
访问
ExploitDB EDB-28754 EXPLOIT
exploitdb
访问
Download Exploit EDB-28754 EXPLOIT
exploitdb
访问
ExploitDB EDB-28755 EXPLOIT
exploitdb
访问
Download Exploit EDB-28755 EXPLOIT
exploitdb
访问
ExploitDB EDB-28756 EXPLOIT
exploitdb
访问
Download Exploit EDB-28756 EXPLOIT
exploitdb
访问
ExploitDB EDB-28757 EXPLOIT
exploitdb
访问
Download Exploit EDB-28757 EXPLOIT
exploitdb
访问
ExploitDB EDB-28758 EXPLOIT
exploitdb
访问
Download Exploit EDB-28758 EXPLOIT
exploitdb
访问
ExploitDB EDB-28759 EXPLOIT
exploitdb
访问
Download Exploit EDB-28759 EXPLOIT
exploitdb
访问
CVSS评分详情
4.3
MEDIUM
CVSS向量: AV:N/AC:M/Au:N/C:N/I:P/A:N
CVSS版本: 2.0
机密性
NONE
完整性
PARTIAL
可用性
NONE
时间信息
发布时间:
2006-10-06 19:00:00
修改时间:
2024-08-07 19:41:05
创建时间:
2025-11-11 15:32:37
更新时间:
2026-01-19 09:42:15
利用信息
此漏洞有可利用代码!
利用代码数量: 17
利用来源:
未知 未知 未知 未知 未知 未知 未知 未知 未知 未知 未知 未知 未知 未知 未知 未知 未知
数据源详情
数据源 记录ID 版本 提取时间
CVE cve_CVE-2006-5190 2025-11-11 15:17:45 2025-11-11 07:32:37
NVD nvd_CVE-2006-5190 2025-11-11 14:51:51 2025-11-11 07:41:23
CNNVD cnnvd_CNNVD-200610-114 2025-11-11 15:08:53 2025-11-11 07:49:10
EXPLOITDB exploitdb_EDB-28743 2025-11-11 15:05:39 2025-11-11 08:24:25
EXPLOITDB exploitdb_EDB-28744 2025-11-11 15:05:39 2025-11-11 08:24:25
EXPLOITDB exploitdb_EDB-28745 2025-11-11 15:05:39 2025-11-11 08:24:25
EXPLOITDB exploitdb_EDB-28746 2025-11-11 15:05:39 2025-11-11 08:24:25
EXPLOITDB exploitdb_EDB-28747 2025-11-11 15:05:39 2025-11-11 08:24:25
EXPLOITDB exploitdb_EDB-28748 2025-11-11 15:05:39 2025-11-11 08:24:25
EXPLOITDB exploitdb_EDB-28749 2025-11-11 15:05:39 2025-11-11 08:24:25
EXPLOITDB exploitdb_EDB-28750 2025-11-11 15:05:39 2025-11-11 08:24:25
EXPLOITDB exploitdb_EDB-28751 2025-11-11 15:05:39 2025-11-11 08:24:25
EXPLOITDB exploitdb_EDB-28752 2025-11-11 15:05:39 2025-11-11 08:24:25
EXPLOITDB exploitdb_EDB-28753 2025-11-11 15:05:39 2025-11-11 08:24:25
EXPLOITDB exploitdb_EDB-28754 2025-11-11 15:05:39 2025-11-11 08:24:25
EXPLOITDB exploitdb_EDB-28755 2025-11-11 15:05:39 2025-11-11 08:24:25
EXPLOITDB exploitdb_EDB-28756 2025-11-11 15:05:39 2025-11-11 08:24:25
EXPLOITDB exploitdb_EDB-28757 2025-11-11 15:05:39 2025-11-11 08:24:25
EXPLOITDB exploitdb_EDB-28758 2025-11-11 15:05:39 2025-11-11 08:24:25
EXPLOITDB exploitdb_EDB-28759 2025-11-11 15:05:39 2025-11-11 08:24:25
版本与语言
当前版本: v20
主要语言: EN
支持语言:
EN ZH
其他标识符:
:
:
:
:
:
:
:
:
:
:
:
:
:
:
:
:
:
:
:
:
:
:
:
:
:
:
:
:
:
:
:
:
:
:
安全公告
暂无安全公告信息
变更历史
v20 EXPLOITDB
2025-11-11 16:24:25
references_count: 72 → 74; tags_count: 19 → 20
查看详细变更
  • references_count: 72 -> 74
  • tags_count: 19 -> 20
v19 EXPLOITDB
2025-11-11 16:24:25
references_count: 70 → 72; tags_count: 18 → 19
查看详细变更
  • references_count: 70 -> 72
  • tags_count: 18 -> 19
v18 EXPLOITDB
2025-11-11 16:24:25
references_count: 68 → 70; tags_count: 17 → 18
查看详细变更
  • references_count: 68 -> 70
  • tags_count: 17 -> 18
v17 EXPLOITDB
2025-11-11 16:24:25
references_count: 66 → 68; tags_count: 16 → 17
查看详细变更
  • references_count: 66 -> 68
  • tags_count: 16 -> 17
v16 EXPLOITDB
2025-11-11 16:24:25
references_count: 64 → 66; tags_count: 15 → 16
查看详细变更
  • references_count: 64 -> 66
  • tags_count: 15 -> 16
v15 EXPLOITDB
2025-11-11 16:24:25
references_count: 62 → 64; tags_count: 14 → 15
查看详细变更
  • references_count: 62 -> 64
  • tags_count: 14 -> 15
v14 EXPLOITDB
2025-11-11 16:24:25
references_count: 60 → 62; tags_count: 13 → 14
查看详细变更
  • references_count: 60 -> 62
  • tags_count: 13 -> 14
v13 EXPLOITDB
2025-11-11 16:24:25
references_count: 58 → 60; tags_count: 12 → 13
查看详细变更
  • references_count: 58 -> 60
  • tags_count: 12 -> 13
v12 EXPLOITDB
2025-11-11 16:24:25
references_count: 56 → 58; tags_count: 11 → 12
查看详细变更
  • references_count: 56 -> 58
  • tags_count: 11 -> 12
v11 EXPLOITDB
2025-11-11 16:24:25
references_count: 54 → 56; tags_count: 10 → 11
查看详细变更
  • references_count: 54 -> 56
  • tags_count: 10 -> 11
v10 EXPLOITDB
2025-11-11 16:24:25
references_count: 52 → 54; tags_count: 9 → 10
查看详细变更
  • references_count: 52 -> 54
  • tags_count: 9 -> 10
v9 EXPLOITDB
2025-11-11 16:24:25
references_count: 50 → 52; tags_count: 8 → 9
查看详细变更
  • references_count: 50 -> 52
  • tags_count: 8 -> 9
v8 EXPLOITDB
2025-11-11 16:24:25
references_count: 48 → 50; tags_count: 7 → 8
查看详细变更
  • references_count: 48 -> 50
  • tags_count: 7 -> 8
v7 EXPLOITDB
2025-11-11 16:24:25
references_count: 46 → 48; tags_count: 6 → 7
查看详细变更
  • references_count: 46 -> 48
  • tags_count: 6 -> 7
v6 EXPLOITDB
2025-11-11 16:24:25
references_count: 44 → 46; tags_count: 5 → 6
查看详细变更
  • references_count: 44 -> 46
  • tags_count: 5 -> 6
v5 EXPLOITDB
2025-11-11 16:24:25
references_count: 42 → 44; tags_count: 4 → 5
查看详细变更
  • references_count: 42 -> 44
  • tags_count: 4 -> 5
v4 EXPLOITDB
2025-11-11 16:24:25
references_count: 39 → 42; tags_count: 0 → 4; data_sources: ['cnnvd', 'cve', 'nvd'] → ['cnnvd', 'cve', 'exploitdb', 'nvd']
查看详细变更
  • references_count: 39 -> 42
  • tags_count: 0 -> 4
  • data_sources: ['cnnvd', 'cve', 'nvd'] -> ['cnnvd', 'cve', 'exploitdb', 'nvd']
v3 CNNVD
2025-11-11 15:49:10
vulnerability_type: 未提取 → 跨站脚本; cnnvd_id: 未提取 → CNNVD-200610-114; data_sources: ['cve', 'nvd'] → ['cnnvd', 'cve', 'nvd']
查看详细变更
  • vulnerability_type: 未提取 -> 跨站脚本
  • cnnvd_id: 未提取 -> CNNVD-200610-114
  • data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
v2 NVD
2025-11-11 15:41:23
cvss_score: 未提取 → 4.3; cvss_vector: NOT_EXTRACTED → AV:N/AC:M/Au:N/C:N/I:P/A:N; cvss_version: NOT_EXTRACTED → 2.0; affected_products_count: 0 → 11; data_sources: ['cve'] → ['cve', 'nvd']
查看详细变更
  • cvss_score: 未提取 -> 4.3
  • cvss_vector: NOT_EXTRACTED -> AV:N/AC:M/Au:N/C:N/I:P/A:N
  • cvss_version: NOT_EXTRACTED -> 2.0
  • affected_products_count: 0 -> 11
  • data_sources: ['cve'] -> ['cve', 'nvd']