CVE Database
/

CVE-2006-3826

Back to search

CVE-2006-3826

Published: Jul 25, 2006

Modified: Aug 7, 2024

PUBLISHED

Description

Multiple cross-site scripting (XSS) vulnerabilities in Kailash Nadh boastMachine (formerly bMachine) 3.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) user_login, (2) full_name, and (3) URL parameters in register.php; and allow remote authenticated administrators to inject arbitrary web script or HTML via the (4) cat_list and (5) key parameters in a certain portion of the admin interface.

VendorProductVersions

n/a

n/a

affected
n/a

References

21066
third-party-advisory
x_refsource_SECUNIA
boastmachine-register-xss(27771)
vdb-entry
x_refsource_XF
1016515
vdb-entry
x_refsource_SECTRACK
ADV-2006-2849
vdb-entry
x_refsource_VUPEN
1252
third-party-advisory
x_refsource_SREASON

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now