Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2006-1430

EPSS 0.81% · P74
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2006-1430

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Multiple cross-site scripting (XSS) vulnerabilities in CONTROLzx HMS (formerly DRZES) 3.3.4 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) dedicatedPlanID parameter to dedicated_order.php, (2) sharedPlanID parameter to shared_order.php, (3) plan_id parameter to customers/server_management.php, and (4) email field to customers/forgotpass.php.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
CONTROLzx HMS多个跨站脚本攻击漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
在CONTROLzx HMS (之前称DRZES) 3.3.4及其早期版本中存在多个跨站脚本攻击(XSS)漏洞,远程攻击者可通过以下途径注入任意Web脚本或HTML:(1) 用于dedicated_order.php中的dedicatedPlanID参数,(2) 用于shared_order.php中的sharedPlanID参数,(3) 用于customers/server_management.php中的plan_id参数,和(4) 用于customers/forgotpass.php中的email字
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2006-1430

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2006-1430

登录查看更多情报信息。

Same Patch Batch · n/a · 2006-03-28 · 42 CVEs total

CVE-2006-1421AkoComment 'akocomment.PHP'多个SQL注入漏洞
CVE-2006-1411Absolute Image Gallery XE多个跨站脚本攻击漏洞
CVE-2006-1412TFT Gallery管理员口令信息泄露漏洞
CVE-2006-1413EZHomePagePro多个跨站脚本攻击漏洞
CVE-2006-1414Toast Forums 'Toast.ASP'多个跨站脚本攻击漏洞
CVE-2006-1415dotNetBB Forums dotNetBB跨站脚本攻击漏洞
CVE-2006-1416Absolute FAQ管理器跨站脚本攻击漏洞
CVE-2006-1417Caloris Planitia Online Quiz System多个跨站脚本攻击漏洞
CVE-2006-1418Caloris Planitia技术学校管理系统跨站脚本攻击漏洞
CVE-2006-1419Nuked-Klan 'Index.PHP' SQL注入漏洞
CVE-2006-1420SaphpLesson 'Print.PHP' SQL注入漏洞
CVE-2006-1410Xigla Absolute Live Support XE多个跨站脚本攻击漏洞
CVE-2006-1422PHPBookingCalendar Details_View.PHP SQL注入漏洞
CVE-2006-1423UBB.threads 'showflat.php'SQL注入漏洞
CVE-2006-1425PHPmyfamily 'Track.PHP'跨站脚本攻击漏洞
CVE-2006-1426Pixel Motion多个SQL注入漏洞
CVE-2006-1427Web-App.Org和Web-App.Net多个跨站脚本攻击漏洞
CVE-2006-1428phpCOIN多个跨站脚本攻击漏洞
CVE-2006-1429ClassifiedZONE Accountlogon.CFM跨站脚本攻击漏洞
CVE-2006-1431FusionZONE CouponZONE ‘local.cfm’跨站脚本攻击漏洞

Showing top 20 of 42 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2006-1430

No comments yet


Leave a comment