Multiple cross-site scripting (XSS) vulnerabilities in admin/actions.php in PHP-Blogger 2.2.5, and possibly earlier versions, allow remote attackers to execute arbitrary web script or HTML via the (1) name, (2) title, (3) news, (4) description, and (5) sitename parameters.
References
Configurations
History
21 Nov 2024, 00:13
Type | Values Removed | Values Added |
---|---|---|
References | () http://secunia.com/advisories/20989 - | |
References | () http://securityreason.com/securityalert/1202 - | |
References | () http://www.securityfocus.com/archive/1/439440/100/0/threaded - | |
References | () http://www.securityfocus.com/bid/18909 - | |
References | () http://www.vupen.com/english/advisories/2006/2710 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/27630 - |
Information
Published : 2006-07-11 23:05
Updated : 2025-04-03 01:03
NVD link : CVE-2006-3514
Mitre link : CVE-2006-3514
CVE.ORG link : CVE-2006-3514
JSON object : View
Products Affected
phpblogger
- php-blogger
CWE