CVE-2006-3049 Information

Description

Multiple cross-site scripting (XSS) vulnerabilities in booking3.php in Mole Group Ticket Booking Script allow remote attackers to inject arbitrary web script or HTML via the (1) name (2) address1 (3) address2 (4) county (5) postcode (6) email (7) phone or (8) mobile parameters to booking2.php.

Reference

http://archives.neohapsis.com/archives/bugtraq/2006-06/0111.html http://secunia.com/advisories/20612 http://www.attrition.org/pipermail/vim/2006-June/000868.html http://www.vupen.com/english/advisories/2006/2305 https://exchange.xforce.ibmcloud.com/vulnerabilities/27150

Share on: