CVE-2006-1406 Information

Description

Multiple cross-site scripting (XSS) vulnerabilities in wbadmlog.aspx in uniForum 4.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) txtuser or (2) txtpassword parameters.

Reference

http://pridels0.blogspot.com/2006/03/uniforum-xss-vuln.html http://secunia.com/advisories/19397 http://www.osvdb.org/24123 http://www.securityfocus.com/bid/17245 http://www.vupen.com/english/advisories/2006/1101 https://exchange.xforce.ibmcloud.com/vulnerabilities/25433

Share on: