CVE-2006-3494 Information
Description
Multiple cross-site scripting (XSS) vulnerabilities in Buddy Zone 1.0.1 allow remote attackers to inject arbitrary HTML and web script via the (1) cat_id parameter to (a) view_classifieds.php; (2) id parameter in (b) view_ad.php; (3) event_id parameter in (c) view_event.php (d) delete_event.php and (e) edit_event.php; and (4) group_id in (f) view_group.php.
Reference
http://secunia.com/advisories/20933 http://securityreason.com/securityalert/1209 http://www.osvdb.org/26979 http://www.osvdb.org/26980 http://www.osvdb.org/26981 http://www.osvdb.org/26982 http://www.osvdb.org/26983 http://www.osvdb.org/26984 http://www.osvdb.org/26985 http://www.osvdb.org/26988 http://www.osvdb.org/26989 http://www.osvdb.org/26990 http://www.osvdb.org/26991 http://www.osvdb.org/26992 http://www.osvdb.org/26993 http://www.securityfocus.com/archive/1/438868/100/0/threaded http://www.securityfocus.com/archive/1/440144/100/100/threaded http://www.securityfocus.com/bid/18759 http://www.vupen.com/english/advisories/2006/2645 https://exchange.xforce.ibmcloud.com/vulnerabilities/27514
Share on: