Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2006-5830
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2006-5830

Description:
Multiple cross-site scripting (XSS) vulnerabilities in All In One Control Panel (AIOCP) 1.3.007 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) topid, (2) forid, and (3) catid parameters to code/cp_forum_view.php; (4) choosed_language parameter to cp_dpage.php; (5) orderdir parameter to cp_links_search.php; (6) order_field parameter to (a) cp_show_ec_products.php and (b) cp_users_online.php; and the (7) signature and (8) fiscal code fields in the user profile.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/30045
  http://xforce.iss.net/xforce/xfdb/30048

SREASON
  http://securityreason.com/securityalert/1839

SAID
  Secunia Advisory: SA22719

MISC
  http://sourceforge.net/project/shownotes.php?release_id=478370

BUGTRAQ
  http://www.securityfocus.com/archive/1/archive/1/450701/100/0/threaded

BID
  20931


Return to the previous page.