Vulnerabilities > CVE-2006-5146 - Cross-Site Scripting vulnerability in Yblog

047910
CVSS 6.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
yblog
exploit available

Summary

Multiple cross-site scripting (XSS) vulnerabilities in Yblog allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter in (a) funk.php, or the (2) action parameter in (b) tem.php and (c) uss.php.

Vulnerable Configurations

Part Description Count
Application
Yblog
1

Exploit-Db

  • descriptionYblog funk.php id Parameter XSS. CVE-2006-5146. Webapps exploit for php platform
    idEDB-ID:28732
    last seen2016-02-03
    modified2006-09-30
    published2006-09-30
    reporterYou_You
    sourcehttps://www.exploit-db.com/download/28732/
    titleYblog funk.php id Parameter XSS
  • descriptionYblog uss.php action Parameter XSS. CVE-2006-5146. Webapps exploit for php platform
    idEDB-ID:28734
    last seen2016-02-03
    modified2006-09-30
    published2006-09-30
    reporterYou_You
    sourcehttps://www.exploit-db.com/download/28734/
    titleYblog uss.php action Parameter XSS
  • descriptionYblog tem.php action Parameter XSS. CVE-2006-5146. Webapps exploit for php platform
    idEDB-ID:28733
    last seen2016-02-03
    modified2006-09-30
    published2006-09-30
    reporterYou_You
    sourcehttps://www.exploit-db.com/download/28733/
    titleYblog tem.php action Parameter XSS