Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Hessamx

#51654of 53,630
4.3Total CVSS
Vulnerabilities · 1
PT-2006-5296
4.3
2006-08-31
Iwebnegar · Iwebnegar · CVE-2006-4496
**Name of the Vulnerable Software and Affected Versions** IwebNegar version 1.1 **Description** A cross-site scripting (XSS) issue exists, allowing remote attackers to inject arbitrary web script or HTML. This is achieved via the `comment` parameter in comments.php. **Recommendations** For IwebNegar version 1.1, consider restricting access to the comments.php file until a patch is available, or avoid using the `comment` parameter in the affected endpoint to minimize the risk of exploitation.