Vulnerabilities > CVE-2006-5064 - Cross-Site Scripting vulnerability in BirdBlog

047910
CVSS 5.1 - MEDIUM
Attack vector
NETWORK
Attack complexity
HIGH
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
high complexity
birdblog
exploit available

Summary

Multiple cross-site scripting (XSS) vulnerabilities in BirdBlog 1.4 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) entryid parameter in comment.php, (2) page parameter in index.php, or the (3) uid parameter in user.php. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

Exploit-Db

  • descriptionBirdBlog 1.x user.php uid Parameter XSS. CVE-2006-5064. Webapps exploit for php platform
    idEDB-ID:28669
    last seen2016-02-03
    modified2006-09-25
    published2006-09-25
    reporterRoot3r_H3ll
    sourcehttps://www.exploit-db.com/download/28669/
    titleBirdBlog 1.x user.php uid Parameter XSS
  • descriptionBirdBlog 1.x comment.php entryid Parameter XSS. CVE-2006-5064. Webapps exploit for php platform
    idEDB-ID:28667
    last seen2016-02-03
    modified2006-09-25
    published2006-09-25
    reporterRoot3r_H3ll
    sourcehttps://www.exploit-db.com/download/28667/
    titleBirdBlog 1.x comment.php entryid Parameter XSS
  • descriptionBirdBlog 1.x index.php page Parameter XSS. CVE-2006-5064. Webapps exploit for php platform
    idEDB-ID:28668
    last seen2016-02-03
    modified2006-09-25
    published2006-09-25
    reporterRoot3r_H3ll
    sourcehttps://www.exploit-db.com/download/28668/
    titleBirdBlog 1.x index.php page Parameter XSS