CVE

CVE-2006-2997

Severity:
Pending analysis
Type:
Unavailable / Other
Publication date:
13/06/2006
Last modified:
18/10/2018

Description

Cross-site scripting (XSS) vulnerability in ZMS 2.9 and earlier, when register_globals is enabled, allows remote attackers to inject arbitrary web script or HTML via the raw parameter in the search field.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:zms_publishing:zms:*:*:*:*:*:*:*:* 2.9.2 (including)