CVE-2006-3956 Information

Description

Multiple cross-site scripting (XSS) vulnerabilities in contact.php in Advanced Webhost Billing System (AWBS) 2.2.2 allow remote attackers to inject arbitrary web script or HTML via the (1) Name (2) AccountUsername and (3) Message parameters.

Reference

http://secunia.com/advisories/21296 http://securityreason.com/securityalert/1317 http://www.osvdb.org/27629 http://www.securityfocus.com/archive/1/441532/100/0/threaded http://www.securityfocus.com/bid/19226 http://www.vupen.com/english/advisories/2006/3061 https://exchange.xforce.ibmcloud.com/vulnerabilities/28069

Share on: