CVE
- Id
- 19462
- CVE No.
- CVE-2006-3358
- Status
- Candidate
- Description
- Multiple cross-site scripting (XSS) vulnerabilities in index.php in NewsPHP 2006 PRO allow remote attackers to inject arbitrary web script or HTML via the (1) words, (2) id, (3) cat_id, and (4) tim parameters, which are not sanitized before being returned in an error page. NOTE: it is possible that some of these vectors are resultant from an SQL injection issue.
- Phase
- Assigned (20060706)
- Votes
- None (candidate not yet proposed)
- Comments