CVE-2006-2340

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
12/05/2006
Last modified:
03/04/2025

Description

Cross-site scripting (XSS) vulnerability in PassMasterFlex and PassMasterFlexPlus (PassMasterFlex+) 1.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) username, (2) password, or (3) User-Agent HTTP header in the Hack Log.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:lethal_penguin:passmasterflex:1.2:*:*:*:*:*:*:*
cpe:2.3:a:lethal_penguin:passmasterflexplus:1.2:*:*:*:*:*:*:*