CVE Database
/

CVE-2006-6197

Back to search

CVE-2006-6197

Published: Dec 1, 2006

Modified: Aug 7, 2024

PUBLISHED

Description

Multiple cross-site scripting (XSS) vulnerabilities in b2evolution 1.8.2 through 1.9 beta allow remote attackers to inject arbitrary web script or HTML via the (1) app_name parameter in (a) _404_not_found.page.php, (b) _410_stats_gone.page.php, and (c) _referer_spam.page.php in inc/VIEW/errors/; the (2) baseurl parameter in (d) inc/VIEW/errors/_404_not_found.page.php; and the (3) ReqURI parameter in (e) inc/VIEW/errors/_referer_spam.page.php.

VendorProductVersions

n/a

n/a

affected
n/a

References

20061128 b2evolution XSS Vulnerabilities
mailing-list
x_refsource_BUGTRAQ
23148
third-party-advisory
x_refsource_SECUNIA
1944
third-party-advisory
x_refsource_SREASON
21334
vdb-entry
x_refsource_BID

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now