First published: Tue May 30 2006(Updated: )
Cross-site scripting (XSS) vulnerability in index.php in Vacation Rental Script 1.0 allows remote attackers to inject arbitrary web script or HTML via the obj parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Vacation Rental Script | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2006-2651 is categorized as medium, given its potential for exploitation via XSS attacks.
To mitigate CVE-2006-2651, validate and sanitize the 'obj' parameter input in index.php to prevent script injection.
CVE-2006-2651 affects Vacation Rental Script version 1.0.
CVE-2006-2651 is a cross-site scripting (XSS) vulnerability.
Yes, CVE-2006-2651 allows remote attackers to execute arbitrary web scripts or HTML through the affected parameter.