CVE-2006-4829 Information
Description
Multiple cross-site scripting (XSS) vulnerabilities in David Czarnecki Blojsom 2.31 allow remote attackers to inject arbitrary web script or HTML via the (1) blog-category-description (2) blog-entry-title (3) rss-enclosure-url (4) technorati-tagsi or (5) blog-category-name parameter in a blog post.
Reference
http://docs.info.apple.com/article.html?artnum=305214 http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html http://secunia.com/advisories/21935 http://secunia.com/advisories/24479 http://securityreason.com/securityalert/1594 http://www.kb.cert.org/vuls/id/425861 http://www.securityfocus.com/archive/1/446009/100/0/threaded http://www.securityfocus.com/bid/20026 http://www.us-cert.gov/cas/techalerts/TA07-072A.html http://www.vupen.com/english/advisories/2006/3633 http://www.vupen.com/english/advisories/2007/0930 https://exchange.xforce.ibmcloud.com/vulnerabilities/28951 Multiple cross-site scripting (XSS) vulnerabilities in David Czarnecki Blojsom 2.31 allow remote attackers to inject arbitrary web script or HTML via the (1) blog-category-description (2) blog-entry-title (3) rss-enclosure-url (4) technorati-tagsi or (5) blog-category-name parameter in a blog post.
Share on: