Vulnerabilities > CVE-2006-1361 - HTML Injection vulnerability in OSWiki Username
Attack vector
NETWORK Attack complexity
MEDIUM Privileges required
NONE Confidentiality impact
NONE Integrity impact
PARTIAL Availability impact
NONE network
oswiki
Summary
Cross-site scripting (XSS) vulnerability in OSWiki before 0.3.1 allows remote attackers to inject arbitrary web script or HTML via the username field to (1) list.rhtml or (2) show.rhtml. This vulnerability is addressed in the following product release: OSWiki, OSWiki, 0.3.1
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |