![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
CVE ID: | CVE-2005-1498 |
Description: | Multiple cross-site scripting (XSS) vulnerabilities in myBloggie 2.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) year parameter in viewmode.php, or the (2) cat_id, (3) month_no, or (4) post_id parameter in index.php, which are not properly sanitized before they are displayed in an error message. NOTE: issues 2, 3, and 4 may be due to a problem in associated products rather than myBloggie itself. |
Test IDs: | None available |
Cross References: |
Common Vulnerability Exposure (CVE) ID: CVE-2005-1498 BugTraq ID: 13507 http://www.securityfocus.com/bid/13507 Bugtraq: 20050505 Multiple vulnerabilities in myBloggie 2.1.1 (Google Search) http://marc.info/?l=bugtraq&m=111531904608224&w=2 http://mywebland.com/forums/viewtopic.php?t=180 XForce ISS Database: mybloggie-script-injection(20436) https://exchange.xforce.ibmcloud.com/vulnerabilities/20436 XForce ISS Database: mybloggie-viewmodephp-xss(20434) https://exchange.xforce.ibmcloud.com/vulnerabilities/20434 |