CVE-2006-2491 Information

Description

Cross-site scripting (XSS) vulnerability in (1) index.php and (2) bmc/admin.php in BoastMachine (bMachine) 3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the query string which is not properly filtered when it is accessed using the $_SERVER[\PHP_SELF] variable.

Reference

http://secunia.com/advisories/20149 http://securityreason.com/securityalert/725 http://securityreason.com/securityalert/927 http://www.osvdb.org/25617 http://www.osvdb.org/25618 http://www.securityfocus.com/archive/1/434294/100/0/threaded http://www.securityfocus.com/bid/18012 http://www.vupen.com/english/advisories/2006/1853 https://exchange.xforce.ibmcloud.com/vulnerabilities/26518

Share on: