CVE-2006-4874 Information

Description

Multiple cross-site scripting (XSS) vulnerabilities in Jupiter CMS allow remote attackers to inject arbitrary web script or HTML via the (1) language[Admin name] and (2) language[Admin back] parameters in (a) modules/blocks.php; the (3) language[Register title] and (4) language[Register title2] parameters in (b) modules/register.php; the (5) language[Mass-Email form title] (6) language[Mass-Email form desc] (7) language[Mass-Email form desc2] (8) language[Mass-Email form desc3] and (9) language[Mass-Email form desc4] parameters in (c) modules/mass-email.php; the (10) language[Forgotten title] (11) language[Forgotten desc] (12) language[Forgotten desc2] (13) language[Forgotten desc3] (14) language[Forgotten desc4] and (15) language[Forgotten desc5] parameters in (d) modules/register.php; and the (16) language[Search view desc] (17) language[Search view desc2] (18) language[Search view desc3] (19) language[Search view desc4] (20) language[Search view desc5] (21) language[Search view desc6] (22) language[Search view desc7] and (23) language[Search view desc8] parameters in (e) modules/search.php.

Reference

http://securityreason.com/securityalert/1608 http://www.securityfocus.com/archive/1/446064/100/0/threaded http://www.securityfocus.com/bid/20048

Share on: