First published: Thu Feb 02 2006(Updated: )
Cross-site scripting (XSS) vulnerability in index.php3 in SPIP 1.8.2-e and earlier and 1.9 Alpha 2 (5539) and earlier allows remote attackers to inject arbitrary web script or HTML via the lang parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Spip | <=1.8.2e | |
Spip | <=1.9_alpha2_5539 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-0518 has a moderate severity rating due to its potential for cross-site scripting attacks.
To fix CVE-2006-0518, upgrade your SPIP installation to version 1.9 or later.
CVE-2006-0518 affects SPIP versions 1.8.2-e and earlier as well as 1.9 Alpha 2 (5539) and earlier.
A cross-site scripting vulnerability like CVE-2006-0518 allows attackers to inject malicious scripts into web pages viewed by users.
Yes, CVE-2006-0518 allows remote attackers to inject arbitrary web scripts or HTML via the lang parameter.