CVE-2006-1072: XSS
Published Mar 8, 2006
·Updated
Cross-site scripting (XSS) vulnerability in Daverave Simplog 1.0.2 and earlier allows remote attackers to inject arbitrary web script or HTML via a blog post.
Affected Software
1 affected component
Simplog Simplog<=1.0.2
Event History
Mar 8, 2006
CVE Published
12:02 AM
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-1072?
CVE-2006-1072 is considered to have a medium severity due to its potential impact on user data and site integrity.
2
How do I fix CVE-2006-1072?
To fix CVE-2006-1072, upgrade to a version of Simplog later than 1.0.2 that patches the XSS vulnerability.
3
What types of attacks are possible with CVE-2006-1072?
CVE-2006-1072 allows for cross-site scripting attacks, where attackers can inject malicious scripts into blog posts.
4
What versions of Simplog are affected by CVE-2006-1072?
CVE-2006-1072 affects Simplog versions 1.0.2 and earlier.
5
Who can exploit CVE-2006-1072?
Remote attackers can exploit CVE-2006-1072 without authentication to inject arbitrary web scripts through blog posts.