CVE-2006-3616

Multiple cross-site scripting (XSS) vulnerabilities in Carbonize Lazarus Guestbook 1.6 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the show parameter in codes-english.php and (2) the img parameter in picture.php, after the name of an existing file.
Configurations

Configuration 1 (hide)

cpe:2.3:a:carbonize:lazarus_guestbook:*:*:*:*:*:*:*:*

History

21 Nov 2024, 00:14

Type Values Removed Values Added
References () http://secunia.com/advisories/21034 - () http://secunia.com/advisories/21034 -
References () http://securitytracker.com/id?1016486 - () http://securitytracker.com/id?1016486 -
References () http://www.osvdb.org/27089 - () http://www.osvdb.org/27089 -
References () http://www.osvdb.org/27090 - () http://www.osvdb.org/27090 -
References () http://www.securityfocus.com/archive/1/439904/100/0/threaded - () http://www.securityfocus.com/archive/1/439904/100/0/threaded -
References () http://www.securityfocus.com/bid/18956 - Exploit () http://www.securityfocus.com/bid/18956 - Exploit
References () http://www.vupen.com/english/advisories/2006/2784 - () http://www.vupen.com/english/advisories/2006/2784 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/27714 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/27714 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/27716 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/27716 -

Information

Published : 2006-07-18 15:46

Updated : 2025-04-03 01:03


NVD link : CVE-2006-3616

Mitre link : CVE-2006-3616

CVE.ORG link : CVE-2006-3616


JSON object : View

Products Affected

carbonize

  • lazarus_guestbook