Multiple cross-site scripting (XSS) vulnerabilities in contact.php in Advanced Webhost Billing System (AWBS) 2.2.2 allow remote attackers to inject arbitrary web script or HTML via the (1) Name, (2) AccountUsername and (3) Message parameters.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 00:14
Type | Values Removed | Values Added |
---|---|---|
References | () http://secunia.com/advisories/21296 - Vendor Advisory | |
References | () http://securityreason.com/securityalert/1317 - | |
References | () http://www.osvdb.org/27629 - | |
References | () http://www.securityfocus.com/archive/1/441532/100/0/threaded - | |
References | () http://www.securityfocus.com/bid/19226 - | |
References | () http://www.vupen.com/english/advisories/2006/3061 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/28069 - |
Information
Published : 2006-08-01 21:04
Updated : 2024-11-21 00:14
NVD link : CVE-2006-3956
Mitre link : CVE-2006-3956
CVE.ORG link : CVE-2006-3956
JSON object : View
Products Affected
total_online_solutions
- advanced_webhost_billing_system
CWE