Multiple cross-site scripting (XSS) vulnerabilities in Web4Future News Portal allow remote attackers to inject arbitrary web script or HTML via the ID parameter to (1) comentarii.php or (2) view.php. NOTE: this issue might be resultant from SQL injection.
References
Configurations
History
21 Nov 2024, 00:10
Type | Values Removed | Values Added |
---|---|---|
References | () http://secunia.com/advisories/17880 - | |
References | () http://securitytracker.com/id?1016027 - Exploit | |
References | () http://www.osvdb.org/25287 - | |
References | () http://www.osvdb.org/25288 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/26259 - |
Information
Published : 2006-05-09 10:02
Updated : 2025-04-03 01:03
NVD link : CVE-2006-2243
Mitre link : CVE-2006-2243
CVE.ORG link : CVE-2006-2243
JSON object : View
Products Affected
web4future
- news_portal
CWE