CVE-2006-2997

NameCVE-2006-2997
DescriptionCross-site scripting (XSS) vulnerability in ZMS 2.9 and earlier, when register_globals is enabled, allows remote attackers to inject arbitrary web script or HTML via the raw parameter in the search field.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs373667

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
zope-zmssource(unstable)(unfixed)unimportant373667

Notes

[sarge] - zope-zms <no-dsa> (Only exploitable with register_globals)
register_globals is an unsupported mode of operation in Debian

Search for package or bug name: Reporting problems