Vulnerabilities > CVE-2006-1791 - Cross-Site Scripting vulnerability in JL Webworks Quickblogger 1.4

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
jl-webworks

Summary

Directory traversal vulnerability in acc.php in QuickBlogger 1.4 allows remote attackers to read or include arbitrary local files via the request parameter. NOTE: this issue can also produce resultant XSS when the associated include statement fails.

Vulnerable Configurations

Part Description Count
Application
Jl_Webworks
1