Secunia Logo
 
CVE Reference: CVE-2006-5127
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2006-5127

Description:
Multiple cross-site scripting (XSS) vulnerabilities in Bartels Schoene ConPresso before 4.0.5a allow remote attackers to inject arbitrary web script or HTML via (1) the nr parameter in detail.php, (2) the msg parameter in db_mysql.inc.php, and (3) the pos parameter in index.php.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/29272

SREASON
  http://securityreason.com/securityalert/1671

SAID
  Secunia Advisory: SA22145

MISC
  http://www.majorsecurity.de/index_2.php?major_rls=major_rls28

CONFIRM
  http://download.compresso.de/compresso-4.0.5a.zip

BUGTRAQ
  http://www.securityfocus.com/archive/1/archive/1/447358/100/0/threaded

BID
  20273


Return to the previous page.