Vulnerabilities > CVE-2006-0443 - HTML Injection vulnerability in Cheesyblog 1.0

047910
CVSS 4.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
cheesyblog
exploit available

Summary

Cross-site scripting (XSS) vulnerability in archive.php in CheesyBlog 1.0 allows remote attackers to inject arbitrary web script or HTML via the (1) realname and (2) comment parameters, or (3) via a javascript URI in the url parameter, when adding a comment.

Vulnerable Configurations

Part Description Count
Application
Cheesyblog
1

Exploit-Db

descriptionCheesyBlog 1.0 Multiple HTML Injection Vulnerabilities. CVE-2006-0443. Webapps exploit for php platform
idEDB-ID:27126
last seen2016-02-03
modified2006-01-25
published2006-01-25
reporterAliaksandr Hartsuyeu
sourcehttps://www.exploit-db.com/download/27126/
titleCheesyBlog 1.0 - Multiple HTML Injection Vulnerabilities