Vulnerabilities > CVE-2006-1205 - Cross-Site Scripting vulnerability in Mywebland Mybloggie 2.1.2/2.1.3/2.1.3Beta
Summary
Multiple cross-site scripting (XSS) vulnerabilities in myWebland myBloggie 2.1.3 beta and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) confirmredirect and (2) post_id parameters in (a) delcomment.php, as reachable when mode=delcom from index.php; and the (3) del and (4) message parameters in (b) upload.php, the (5) errormsg parameter in (c) addcat.php, (d) edituser.php, (e) adduser.php, and (f) editcat.php, the (6) trackback_url parameter in (g) add.php, (7) id parameter in (h) deluser.php, (8) cat_id parameter in (i) delcat.php, and (9) post_id parameter in (j) del.php, as reachable from admin.php.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 3 |
Exploit-Db
description myBloggie 2.1.2/2.1.3 del.php post_id Parameter XSS. CVE-2006-1205. Webapps exploit for php platform id EDB-ID:27389 last seen 2016-02-03 modified 2006-03-09 published 2006-03-09 reporter [email protected] source https://www.exploit-db.com/download/27389/ title myBloggie 2.1.2/2.1.3 del.php post_id Parameter XSS description myBloggie 2.1.2/2.1.3 addcat.php errormsg Parameter XSS. CVE-2006-1205. Webapps exploit for php platform id EDB-ID:27383 last seen 2016-02-03 modified 2006-03-09 published 2006-03-09 reporter [email protected] source https://www.exploit-db.com/download/27383/ title myBloggie 2.1.2/2.1.3 addcat.php errormsg Parameter XSS description myBloggie 2.1.2/2.1.3 upload.php Multiple Parameter XSS. CVE-2006-1205. Webapps exploit for php platform id EDB-ID:27380 last seen 2016-02-03 modified 2006-03-09 published 2006-03-09 reporter [email protected] source https://www.exploit-db.com/download/27380/ title myBloggie 2.1.2/2.1.3 upload.php Multiple Parameter XSS description myBloggie 2.1.2/2.1.3 edituser.php errormsg Parameter XSS. CVE-2006-1205. Webapps exploit for php platform id EDB-ID:27384 last seen 2016-02-03 modified 2006-03-09 published 2006-03-09 reporter [email protected] source https://www.exploit-db.com/download/27384/ title myBloggie 2.1.2/2.1.3 edituser.php errormsg Parameter XSS description myBloggie 2.1.2/2.1.3 delcat.php cat_id Parameter XSS. CVE-2006-1205. Webapps exploit for php platform id EDB-ID:27388 last seen 2016-02-03 modified 2006-03-09 published 2006-03-09 reporter [email protected] source https://www.exploit-db.com/download/27388/ title myBloggie 2.1.2/2.1.3 delcat.php cat_id Parameter XSS description myBloggie 2.1.2/2.1.3 adduser.php errormsg Parameter XSS. CVE-2006-1205. Webapps exploit for php platform id EDB-ID:27385 last seen 2016-02-03 modified 2006-03-09 published 2006-03-09 reporter [email protected] source https://www.exploit-db.com/download/27385/ title myBloggie 2.1.2/2.1.3 adduser.php errormsg Parameter XSS description myBloggie 2.1.2/2.1.3 deluser.php 'id' Parameter XSS. CVE-2006-1205. Webapps exploit for php platform id EDB-ID:27382 last seen 2016-02-03 modified 2006-03-09 published 2006-03-09 reporter [email protected] source https://www.exploit-db.com/download/27382/ title myBloggie 2.1.2/2.1.3 deluser.php 'id' Parameter XSS description myBloggie 2.1.2/2.1.3 editcat.php errormsg Parameter XSS. CVE-2006-1205 . Webapps exploit for php platform id EDB-ID:27386 last seen 2016-02-03 modified 2006-03-09 published 2006-03-09 reporter [email protected] source https://www.exploit-db.com/download/27386/ title myBloggie 2.1.2/2.1.3 editcat.php errormsg Parameter XSS description myBloggie 2.1.2/2.1.3 add.php trackback_url Parameter XSS. CVE-2006-1205. Webapps exploit for php platform id EDB-ID:27387 last seen 2016-02-03 modified 2006-03-09 published 2006-03-09 reporter [email protected] source https://www.exploit-db.com/download/27387/ title myBloggie 2.1.2/2.1.3 add.php trackback_url Parameter XSS description myBloggie 2.1.2/2.1.3 delcomment.php Multiple Parameter XSS. CVE-2006-1205. Webapps exploit for php platform id EDB-ID:27381 last seen 2016-02-03 modified 2006-03-09 published 2006-03-09 reporter [email protected] source https://www.exploit-db.com/download/27381/ title myBloggie 2.1.2/2.1.3 delcomment.php Multiple Parameter XSS
References
- http://www.osvdb.org/23973
- http://www.osvdb.org/23974
- http://www.osvdb.org/23975
- http://www.osvdb.org/23986
- http://www.osvdb.org/23987
- http://www.osvdb.org/23988
- http://www.osvdb.org/23989
- http://www.osvdb.org/23990
- http://www.osvdb.org/23991
- http://www.osvdb.org/23992
- http://www.seclab.tuwien.ac.at/advisories/TUVSA-0603-002.txt
- http://www.securityfocus.com/archive/1/427182/100/0/threaded
- http://www.securityfocus.com/bid/17048
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25134