CVE-2006-1290

Multiple cross-site scripting (XSS) vulnerabilities in Milkeyway Captive Portal 0.1 and 0.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) ipAddress, (2) act, (3) username, and (4) unspecified other parameters in (a) authuser.php; and the (5) username and (6) unspecified other parameters in (b) userstatistics.php.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:milkeyway:milkeyway_captive_portal:0.1:*:*:*:*:*:*:*
cpe:2.3:a:milkeyway:milkeyway_captive_portal:0.1.1:*:*:*:*:*:*:*

History

No history.

Information

Published : 2006-03-19 23:02

Updated : 2024-02-04 16:52


NVD link : CVE-2006-1290

Mitre link : CVE-2006-1290

CVE.ORG link : CVE-2006-1290


JSON object : View

Products Affected

milkeyway

  • milkeyway_captive_portal