CVE-2006-0923: XSS
Published Feb 28, 2006
·Updated
Multiple cross-site scripting (XSS) vulnerabilities in MyPHPNuke (MPN) 1.88 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the letter parameter in reviews.php and (2) the dcategory parameter in download.php.
Affected Software
3 affected components
myPHPNuke myPHPNuke<=1.8.8
myPHPNuke myPHPNuke=1.8.8_8_rc2
myPHPNuke myPHPNuke=1.8.8_7
Event History
Feb 28, 2006
CVE Published
11:02 AM
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-0923?
CVE-2006-0923 has been classified as a medium severity vulnerability.
2
How do I fix CVE-2006-0923?
To fix CVE-2006-0923, upgrade MyPHPNuke to version 1.89 or later.
3
What are the affected versions of MyPHPNuke for CVE-2006-0923?
The affected versions for CVE-2006-0923 are MyPHPNuke 1.88 and earlier.
4
What kind of vulnerability is CVE-2006-0923?
CVE-2006-0923 is a cross-site scripting (XSS) vulnerability that allows attackers to inject arbitrary HTML or web scripts.
5
Which parameters are involved in CVE-2006-0923?
CVE-2006-0923 involves the 'letter' parameter in reviews.php and the 'dcategory' parameter in download.php.