Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Vampire_Chiristof

#51508of 53,622
4.3Total CVSS
Vulnerabilities · 1
PT-2006-5041
4.3
2006-08-18
Vwar · Virtual War · CVE-2006-4224
**Name of the Vulnerable Software and Affected Versions** Virtual War (VWar) versions 1.5.0 and earlier **Description** A cross-site scripting (XSS) issue exists, allowing remote attackers to inject arbitrary web script or HTML via the `year` parameter in the calendar.php file. **Recommendations** For versions 1.5.0 and earlier, consider restricting access to the calendar.php file until a fix is available, and avoid using the `year` parameter in this context to minimize the risk of exploitation.