Cross-site scripting (XSS) vulnerability in comments.php in Maran PHP Blog (Maran Blog), possibly only versions before 20070610, allows remote attackers to inject arbitrary web script or HTML via the id parameter.
Link | Tags |
---|---|
http://www.secvsn.com/content/Advisories/sr-060607-maran.html | vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/34812 | vdb entry |
http://secunia.com/advisories/25616 | third party advisory patch vendor advisory |
http://www.securityfocus.com/bid/24409 | exploit vdb entry patch |
http://www.vupen.com/english/advisories/2007/2148 | vdb entry |
http://www.securityfocus.com/archive/1/494549/100/0/threaded | mailing list |
http://www.securityfocus.com/archive/1/471046/100/0/threaded | mailing list |
http://osvdb.org/35374 | vdb entry |
http://www.securityfocus.com/bid/30309 | vdb entry |
http://securityreason.com/securityalert/2797 | third party advisory |