Vulnerabilities > CVE-2006-1397 - Input Validation vulnerability in PHPAdsNew and PHPPGAds
Attack vector
NETWORK Attack complexity
MEDIUM Privileges required
NONE Confidentiality impact
NONE Integrity impact
PARTIAL Availability impact
NONE Summary
Multiple cross-site scripting (XSS) vulnerabilities in (a) phpAdsNew and (b) phpPgAds before 2.0.8 allow remote attackers to inject arbitrary web script or HTML via the (1) certain parameters to the banner delivery module, which is not properly handled in the administrator interface, or (2) certain parameters to the login form.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 7 | |
Application | 4 |
References
- http://phpadsnew.com/two/nucleus/index.php?itemid=46
- http://secunia.com/advisories/19384
- http://securityreason.com/securityalert/633
- http://securitytracker.com/id?1015828
- http://securitytracker.com/id?1015829
- http://sourceforge.net/project/shownotes.php?release_id=404963
- http://sourceforge.net/project/shownotes.php?release_id=404964
- http://www.osvdb.org/24205
- http://www.osvdb.org/24206
- http://www.securityfocus.com/archive/1/428898/100/0/threaded
- http://www.securityfocus.com/bid/17251
- http://www.vupen.com/english/advisories/2006/1107
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25458