MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in David Czarnecki Blojsom 2.31 allow remote attackers to inject arbitrary web script or HTML via the (1) blog-category-description, (2) blog-entry-title, (3) rss-enclosure-url, (4) technorati-tagsi, or (5) blog-category-name parameter in a blog post
Published Sep 15, 2006
6.8
MEDIUMCVSS 2.0
EPSS 8.88%
Description
Multiple cross-site scripting (XSS) vulnerabilities in David Czarnecki Blojsom 2.31 allow remote attackers to inject arbitrary web script or HTML via the (1) blog-category-description, (2) blog-entry-title, (3) rss-enclosure-url, (4) technorati-tagsi, or (5) blog-category-name parameter in a blog post.
Affected products
Remediation
No remediation recorded yet.
Weaknesses (0)
No CWE recorded.
References (13)
- http://docs.info.apple.com/article.html?artnum=305214 x_refsource_CONFIRM
- http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html vendor-advisoryx_refsource_APPLE
- http://secunia.com/advisories/21935 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/24479 third-party-advisoryx_refsource_SECUNIA
- http://securityreason.com/securityalert/1594 third-party-advisoryx_refsource_SREASON
- http://www.kb.cert.org/vuls/id/425861 third-party-advisoryx_refsource_CERT-VNUS Government Resource
- http://www.securityfocus.com/archive/1/446009/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/bid/20026 vdb-entryx_refsource_BIDExploitPatch
- http://www.us-cert.gov/cas/techalerts/TA07-072A.html third-party-advisoryx_refsource_CERTUS Government Resource
- http://www.vupen.com/english/advisories/2006/3633 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2007/0930 vdb-entryx_refsource_VUPEN
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2006-4816 Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/28951 vdb-entryx_refsource_XF
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Sep 15, 2006
Updated Aug 7, 2024
Reserved Sep 15, 2006
Link CVE-2006-4829
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2006-4816 Assigner mitre
Published Sep 15, 2006
Updated Aug 7, 2024
Exploited since n/a
Link EUVD-2006-4816