MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in Simple PHP Blog (SPHPBlog), probably 0.4.8, allow remote attackers to inject arbitrary web script or HTML via (1) the action parameter in add_block.php or (2) the entry parameter in index.php, different vectors than CVE-2005-1135
Published Nov 21, 2006
6.8
MEDIUMCVSS 2.0
EPSS 1.24%
Description
Affected products
Remediation
Metrics
References (3)
Change history (0)
No recorded changes yet.