Back to search
CVE-2006-0361
Published: Jan 22, 2006
Modified: Aug 7, 2024
PUBLISHED
Description
Cross-site scripting (XSS) vulnerability in addcomment.php in Bit 5 Blog 8.01 allows remote attackers to inject arbitrary web script or HTML via a javascript URI in an <a> tag in the comment parameter, which strips most tags but not <a>.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
http://evuln.com/vulns/32/exploit
x_refsource_MISC
18464
third-party-advisory
x_refsource_SECUNIA
16246
vdb-entry
x_refsource_BID
bit5blog-addcomment-xss(24129)
vdb-entry
x_refsource_XF
http://evuln.com/vulns/32/summary/
x_refsource_MISC
20060115 [eVuln] Bit 5 Blog JavaScript Insertion Vulnerability
mailing-list
x_refsource_BUGTRAQ
22446
vdb-entry
x_refsource_OSVDB
ADV-2006-0195
vdb-entry
x_refsource_VUPEN
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now