Vulnerabilities > CVE-2006-0361 - HTML Injection vulnerability in BIT 5 Blog BIT 5 Blog 8.01

047910
CVSS 4.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
bit-5-blog
exploit available

Summary

Cross-site scripting (XSS) vulnerability in addcomment.php in Bit 5 Blog 8.01 allows remote attackers to inject arbitrary web script or HTML via a javascript URI in an <a> tag in the comment parameter, which strips most tags but not <a>.

Vulnerable Configurations

Part Description Count
Application
Bit_5_Blog
1

Exploit-Db

descriptionBit 5 Blog 8.1 AddComment.PHP HTML Injection Vulnerability. CVE-2006-0361. Webapps exploit for php platform
idEDB-ID:27085
last seen2016-02-03
modified2006-01-16
published2006-01-16
reporterAliaksandr Hartsuyeu
sourcehttps://www.exploit-db.com/download/27085/
titleBit 5 Blog 8.1 AddComment.PHP HTML Injection Vulnerability