CVE

Id
20194  
CVE No.
CVE-2006-4090  
Status
Candidate  
Description
Cross-site scripting (XSS) vulnerability in Webligo BlogHoster 2.2 allows remote attackers to inject arbitrary web script or HTML via the "From: part of the comment post," probably involving the nickname parameter to previewcomment.php.  
Phase
Assigned (20060810)  
Votes
None (candidate not yet proposed)  
Comments