Vulnerabilities > CVE-2006-0846 - HTML Injection vulnerability in Leif M. Wright web Blog 3.5
Attack vector
NETWORK Attack complexity
MEDIUM Privileges required
NONE Confidentiality impact
NONE Integrity impact
PARTIAL Availability impact
NONE network
leif-m-wright
Summary
Multiple cross-site scripting (XSS) vulnerabilities in Leif M. Wright's Blog 3.5 allow remote attackers to inject arbitrary web script or HTML via the (1) Referer and (2) User-Agent HTTP headers, which are stored in a log file and not sanitized when the administrator views the "Log" page, possibly using the ViewCommentsLog function.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |