CVE-2006-1165
published 2006-03-12CVE-2006-1165: Cross-site scripting (XSS) vulnerability in the mediamanager module in DokuWiki before 2006-03-05 allows remote attackers to inject arbitrary web script or…
PriorityP415medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
1.21%
65.0th percentile
Cross-site scripting (XSS) vulnerability in the mediamanager module in DokuWiki before 2006-03-05 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors relating to "handling EXIF data."
Affected
31 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| andreas_gohr | dokuwiki | — | — |
| andreas_gohr | dokuwiki | — | — |
| andreas_gohr | dokuwiki | — | — |
| andreas_gohr | dokuwiki | — | — |
| andreas_gohr | dokuwiki | — | — |
| andreas_gohr | dokuwiki | — | — |
| andreas_gohr | dokuwiki | — | — |
| andreas_gohr | dokuwiki | — | — |
| andreas_gohr | dokuwiki | — | — |
| andreas_gohr | dokuwiki | — | — |
| andreas_gohr | dokuwiki | — | — |
| andreas_gohr | dokuwiki | — | — |
| andreas_gohr | dokuwiki | — | — |
| andreas_gohr | dokuwiki | — | — |
| andreas_gohr | dokuwiki | — | — |
| andreas_gohr | dokuwiki | — | — |
| andreas_gohr | dokuwiki | — | — |
| andreas_gohr | dokuwiki | — | — |
| andreas_gohr | dokuwiki | — | — |
| andreas_gohr | dokuwiki | — | — |
| andreas_gohr | dokuwiki | — | — |
| andreas_gohr | dokuwiki | — | — |
| andreas_gohr | dokuwiki | — | — |
| andreas_gohr | dokuwiki | — | — |
| andreas_gohr | dokuwiki | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv4.3MEDIUM
vendor_redhat5.0MEDIUM
vendor_debian4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-cw28-j5q4-x7vv: Cross-site scripting (XSS) vulnerability in the mediamanager module in DokuWiki before 2006-03-05 allows remote attackers to inject arbitrary web scri
ghsa_unreviewed·2022-05-01
CVE-2006-1165 [MEDIUM] GHSA-cw28-j5q4-x7vv: Cross-site scripting (XSS) vulnerability in the mediamanager module in DokuWiki before 2006-03-05 allows remote attackers to inject arbitrary web scri
Cross-site scripting (XSS) vulnerability in the mediamanager module in DokuWiki before 2006-03-05 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors relating to "handling EXIF data."
OSV
CVE-2006-1165: Cross-site scripting (XSS) vulnerability in the mediamanager module in DokuWiki before 2006-03-05 allows remote attackers to inject arbitrary web scri
osv·2006-03-12·CVSS 4.3
CVE-2006-1165 [MEDIUM] CVE-2006-1165: Cross-site scripting (XSS) vulnerability in the mediamanager module in DokuWiki before 2006-03-05 allows remote attackers to inject arbitrary web scri
Cross-site scripting (XSS) vulnerability in the mediamanager module in DokuWiki before 2006-03-05 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors relating to "handling EXIF data."
Red Hat
openssl: mime_param_cmp NULL dereference crash
vendor_redhat·2012-03-12·CVSS 5.0
CVE-2012-1165 [MEDIUM] CWE-476 openssl: mime_param_cmp NULL dereference crash
openssl: mime_param_cmp NULL dereference crash
The mime_param_cmp function in crypto/asn1/asn_mime.c in OpenSSL before 0.9.8u and 1.x before 1.0.0h allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted S/MIME message, a different vulnerability than CVE-2006-7250.
Package: openssl (Red Hat Enterprise Linux 4) - Will not fix
Package: openssl096b (Red Hat Enterprise Linux 4) - Will not fix
Package: openssl097a (Red Hat Enterprise Linux 5) - Will not fix
Package: openssl098e (Red Hat Enterprise Linux 6) - Will not fix
Package: openssl (Red Hat JBoss Enterprise Web Server 1) - Affected
Debian
CVE-2006-1165: dokuwiki - Cross-site scripting (XSS) vulnerability in the mediamanager module in DokuWiki ...
vendor_debian·2006·CVSS 4.3
CVE-2006-1165 [MEDIUM] CVE-2006-1165: dokuwiki - Cross-site scripting (XSS) vulnerability in the mediamanager module in DokuWiki ...
Cross-site scripting (XSS) vulnerability in the mediamanager module in DokuWiki before 2006-03-05 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors relating to "handling EXIF data."
Scope: local
bookworm: resolved (fixed in 0.0.20060309-3)
bullseye: resolved (fixed in 0.0.20060309-3)
forky: resolved (fixed in 0.0.20060309-3)
sid: resolved (fixed in 0.0.20060309-3)
trixie: resolved (fixed in 0.0.20060309-3)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/19186http://wiki.splitbrain.org/wiki%3Achangeshttp://www.securityfocus.com/bid/17065http://www.vupen.com/english/advisories/2006/0909https://exchange.xforce.ibmcloud.com/vulnerabilities/25137http://secunia.com/advisories/19186http://wiki.splitbrain.org/wiki%3Achangeshttp://www.securityfocus.com/bid/17065http://www.vupen.com/english/advisories/2006/0909https://exchange.xforce.ibmcloud.com/vulnerabilities/25137
2006-03-12
Published