Vulnerabilities > CVE-2006-6211 - Cross-Site Scripting vulnerability in Birdblog 1.4.0

047910
CVSS 6.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
birdblog
exploit available

Summary

Multiple cross-site scripting (XSS) vulnerabilities in BirdBlog 1.4.0 allow remote attackers to inject arbitrary web script or HTML via the (1) msg parameter to (a) admin/admincore.php, the (2) month parameter to (b) admin/comments.php or (c) admin/entries.php, or the (3) page parameter to (d) admin/logs.php, different vectors than CVE-2006-5064.

Vulnerable Configurations

Part Description Count
Application
Birdblog
1

Exploit-Db

  • descriptionBirdBlog 1.4 /admin/comments.php month Parameter XSS. CVE-2006-6211. Webapps exploit for php platform
    idEDB-ID:29099
    last seen2016-02-03
    modified2006-11-20
    published2006-11-20
    reporterthe_Edit0r
    sourcehttps://www.exploit-db.com/download/29099/
    titleBirdBlog 1.4 /admin/comments.php month Parameter XSS
  • descriptionBirdBlog 1.4 /admin/logs.php page Parameter XSS. CVE-2006-6211. Webapps exploit for php platform
    idEDB-ID:29101
    last seen2016-02-03
    modified2006-11-20
    published2006-11-20
    reporterthe_Edit0r
    sourcehttps://www.exploit-db.com/download/29101/
    titleBirdBlog 1.4 /admin/logs.php page Parameter XSS
  • descriptionBirdBlog 1.4 /admin/entries.php month Parameter XSS. CVE-2006-6211. Webapps exploit for php platform
    idEDB-ID:29100
    last seen2016-02-03
    modified2006-11-20
    published2006-11-20
    reporterthe_Edit0r
    sourcehttps://www.exploit-db.com/download/29100/
    titleBirdBlog 1.4 /admin/entries.php month Parameter XSS
  • descriptionBirdBlog 1.4 /admin/admincore.php msg Parameter XSS. CVE-2006-6211. Webapps exploit for php platform
    idEDB-ID:29098
    last seen2016-02-03
    modified2006-11-20
    published2006-11-20
    reporterthe_Edit0r
    sourcehttps://www.exploit-db.com/download/29098/
    titleBirdBlog 1.4 /admin/admincore.php msg Parameter XSS