Vulnerabilities > CVE-2006-1822 - Cross-Site Scripting vulnerability in FarsiNews Search.PHP

047910
CVSS 5.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
NONE
network
farsinews
exploit available

Summary

Cross-site scripting (XSS) vulnerability in search.php in FarsiNews 2.5.3 Pro and earlier allows remote attackers to inject arbitrary web script or HTML via the selected_search_arch parameter.

Exploit-Db

descriptionFarsiNews 2.1/2.5 Search.PHP Cross-Site Scripting Vulnerability. CVE-2006-1822 . Webapps exploit for php platform
idEDB-ID:27650
last seen2016-02-03
modified2006-04-14
published2006-04-14
reporteramin emami
sourcehttps://www.exploit-db.com/download/27650/
titleFarsiNews 2.1/2.5 - Search.PHP Cross-Site Scripting Vulnerability