CVE Database
/

CVE-2006-3327

Back to search

CVE-2006-3327

Published: Jun 30, 2006

Modified: Aug 7, 2024

PUBLISHED

Description

Cross-site scripting (XSS) vulnerability in Custom dating biz dating script 1.0 allows remote attackers to inject arbitrary web script or HTML via the (1) sn20_special_cases parameter ("Special Cases" field) in profile/mini.php, (2) tyxx01_album_name parameter ("Album Name" field) in profile/photo_create.php, and the (3) u parameter in admin/user_view.php.

VendorProductVersions

n/a

n/a

affected
n/a

References

ADV-2006-2534
vdb-entry
x_refsource_VUPEN
20839
third-party-advisory
x_refsource_SECUNIA
18626
vdb-entry
x_refsource_BID
20060622 Dating biz@ dating script v1.0 - XSS
mailing-list
x_refsource_BUGTRAQ

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now