Vulnerabilities > Oicgroup > Exponent CMS > 0.96.6

DATE CVE VULNERABILITY TITLE RISK
2008-04-27 CVE-2008-1972 Cross-Site Scripting vulnerability in Oicgroup Exponent CMS
Multiple cross-site scripting (XSS) vulnerabilities in the user account creation feature in Exponent CMS 0.96.6-GA20071003 and earlier, when the Allow Registration? configuration option is enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) username, (2) firstname, (3) lastname, and (4) e-mail address fields.
network
oicgroup CWE-79
4.3