CVE-2006-0683 Information

Description

Cross-site scripting (XSS) vulnerability in Virtual Hosting Control System (VHCS) 2.4.7.1 with v.1 patch and earlier allows remote attackers to inject arbitrary web script or HTML via the username which is recorded in a log file but not properly handled when the administrator uses the admin log utility to read the log file.

Reference

http://secunia.com/advisories/18799 http://www.rs-labs.com/adv/RS-Labs-Advisory-2006-1.txt http://www.securityfocus.com/archive/1/424816/100/0/threaded http://www.securityfocus.com/bid/16600 http://www.vupen.com/english/advisories/2006/0534 https://exchange.xforce.ibmcloud.com/vulnerabilities/24664

Share on: