CVE-2006-1850 Information
Feb 14, 2021
cve
Description
Multiple cross-site scripting (XSS) vulnerabilities in xFlow 5.46.11 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) level (2) position (3) id and (4) action parameters to members_only/index.cgi and the (5) page parameter to customer_area/index.cgi.
Reference
http://pridels0.blogspot.com/2006/04/xflow-v5x-multiple-vuln.html http://secunia.com/advisories/19707 http://www.securityfocus.com/bid/17614 http://www.vupen.com/english/advisories/2006/1412 https://exchange.xforce.ibmcloud.com/vulnerabilities/25854
Share on: