CVE-2006-3061

Multiple cross-site scripting (XSS) vulnerabilities in 5 Star Review allow remote attackers to inject arbitrary web script or HTML via the (1) sort parameter in index2.php, (2) item_id parameter in report.php, (3) search_term parameter (aka the "search box") in search_reviews.php, (4) the profile field in usercp/profile_edit1.php, and the (5) review field in review_form.php.
Configurations

Configuration 1 (hide)

cpe:2.3:a:review-script.com:five_star_review_script:*:*:*:*:*:*:*:*

History

21 Nov 2024, 00:12

Type Values Removed Values Added
References () http://secunia.com/advisories/20613 - Vendor Advisory () http://secunia.com/advisories/20613 - Vendor Advisory
References () http://securityreason.com/securityalert/1107 - () http://securityreason.com/securityalert/1107 -
References () http://www.osvdb.org/26496 - () http://www.osvdb.org/26496 -
References () http://www.osvdb.org/26497 - () http://www.osvdb.org/26497 -
References () http://www.osvdb.org/26498 - () http://www.osvdb.org/26498 -
References () http://www.osvdb.org/26499 - () http://www.osvdb.org/26499 -
References () http://www.securityfocus.com/archive/1/436771/100/0/threaded - () http://www.securityfocus.com/archive/1/436771/100/0/threaded -
References () http://www.securityfocus.com/bid/18390 - Exploit () http://www.securityfocus.com/bid/18390 - Exploit
References () http://www.vupen.com/english/advisories/2006/2346 - Vendor Advisory () http://www.vupen.com/english/advisories/2006/2346 - Vendor Advisory
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/27188 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/27188 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/27189 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/27189 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/27190 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/27190 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/27192 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/27192 -

Information

Published : 2006-06-19 10:02

Updated : 2024-11-21 00:12


NVD link : CVE-2006-3061

Mitre link : CVE-2006-3061

CVE.ORG link : CVE-2006-3061


JSON object : View

Products Affected

review-script.com

  • five_star_review_script
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')