PT-2005-4166 · Sparkleblog · Sparkleblog

Sikik

·

Published

2005-10-29

·

Updated

2016-10-18

·

CVE-2005-3367

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions SparkleBlog version 2.1
Description A cross-site scripting (XSS) issue exists, allowing remote attackers to inject arbitrary web script or HTML via the name field in the journal.php file.
Recommendations For SparkleBlog version 2.1, consider restricting input to the name field in the journal.php file to prevent arbitrary web script or HTML injection until a patch is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-3367

Affected Products

Sparkleblog