Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Pavithra Hanchagaiah

Researcher fromOS2A
#51191of 53,633
4.3Total CVSS
Vulnerabilities · 1
PT-2006-4389
4.3
2006-07-11
Php · Phpblogger · CVE-2006-3514
**Name of the Vulnerable Software and Affected Versions** PHP-Blogger versions 2.2.5 and earlier **Description** The issue concerns multiple cross-site scripting (XSS) vulnerabilities. These vulnerabilities allow remote attackers to execute arbitrary web script or HTML via the `name`, `title`, `news`, `description`, and `sitename` parameters in the admin/actions.php file. **Recommendations** For PHP-Blogger versions 2.2.5 and earlier, consider restricting access to the admin/actions.php file until a fix is available. As a temporary workaround, avoid using the `name`, `title`, `news`, `description`, and `sitename` parameters in the affected file. At the moment, there is no information about a newer version that contains a fix for this vulnerability.