Secunia Logo
 
CVE Reference: CVE-2008-0723
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2008-0723

Description:
Cross-site scripting (XSS) vulnerability in mynews.inc.php in MyNews 1.6.4, and other earlier 1.6.x versions, allows remote attackers to inject arbitrary web script or HTML via the hash parameter in an admin action to index.php, a different vulnerability than CVE-2006-2208.1.

CVE Status:
Candidate

References:

FULLDISC
  http://marc.info/?l=full-disclosure&m=120232523420188&w=2
  http://marc.info/?l=full-disclosure&m=120235668406688&w=2

BID
  27652


Return to the previous page.