PT-2006-1539 · Unknown · My Little Homepage

Aliaksandr Hartsuyeu

·

Published

2006-01-31

·

Updated

2018-10-19

·

CVE-2006-0473

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions my little homepage my little weblog version as last modified in April 2004
Description The issue concerns a cross-site scripting (XSS) vulnerability in the bbcode function within weblog.php. This vulnerability allows remote attackers to inject arbitrary Javascript via a javascript URI in BBcode link tags.
Recommendations For my little homepage my little weblog version as last modified in April 2004, consider disabling the bbcode function in weblog.php to prevent exploitation until a fix is available. Restrict the use of javascript URIs in BBcode link tags to minimize the risk of XSS attacks.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-0473

Affected Products

My Little Homepage