Vulnerabilities > CVE-2006-1233 - Unspecified vulnerability in Mikael Software Wmnews

047910
CVSS 0.0 - NONE
Attack vector
UNKNOWN
Attack complexity
UNKNOWN
Privileges required
UNKNOWN
Confidentiality impact
UNKNOWN
Integrity impact
UNKNOWN
Availability impact
UNKNOWN
mikael-software
exploit available

Summary

Multiple cross-site scripting (XSS) vulnerabilities in WMNews allow remote attackers to inject arbitrary web script or HTML via the (1) ArtCat parameter to wmview.php, (2) ctrrowcol parameter to footer.php, or (3) ArtID parameter to wmcomments.php.

Vulnerable Configurations

Part Description Count
Application
Mikael_Software
1

Exploit-Db

  • descriptionWMNews 0 wmcomments.php ArtID Parameter XSS. CVE-2006-1233. Webapps exploit for php platform
    idEDB-ID:27417
    last seen2016-02-03
    modified2006-03-10
    published2006-03-10
    reporterR00T3RR0R
    sourcehttps://www.exploit-db.com/download/27417/
    titleWMNews - wmcomments.php ArtID Parameter XSS
  • descriptionWMNews 0 footer.php ctrrowcol Parameter XSS. CVE-2006-1233. Webapps exploit for php platform
    idEDB-ID:27416
    last seen2016-02-03
    modified2006-03-10
    published2006-03-10
    reporterR00T3RR0R
    sourcehttps://www.exploit-db.com/download/27416/
    titleWMNews - footer.php ctrrowcol Parameter XSS
  • descriptionWMNews 0 wmview.php ArtCat Parameter XSS. CVE-2006-1233. Webapps exploit for php platform
    idEDB-ID:27415
    last seen2016-02-03
    modified2006-03-10
    published2006-03-10
    reporterR00T3RR0R
    sourcehttps://www.exploit-db.com/download/27415/
    titleWMNews - wmview.php ArtCat Parameter XSS