Vulnerabilities > CVE-2006-1582 - Cross-Site Scripting vulnerability in Blanknberg 0.2

047910
CVSS 5.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
NONE
network
blanknberg
exploit available

Summary

Cross-site scripting (XSS) vulnerability in index.php in Blank'N'Berg 0.2 allows remote attackers to inject arbitrary web script or HTML via the _path parameter. NOTE: this might be resultant from the directory traversal issue.

Vulnerable Configurations

Part Description Count
Application
Blanknberg
1

Exploit-Db

descriptionBlank'N'Berg 0.2 Cross-Site Scripting Vulnerability. CVE-2006-1582. Webapps exploit for php platform
idEDB-ID:27551
last seen2016-02-03
modified2006-03-31
published2006-03-31
reporterAmine ABOUD
sourcehttps://www.exploit-db.com/download/27551/
titleBlank'N'Berg 0.2 - Cross-Site Scripting Vulnerability