First published: Thu Jul 13 2006(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in Arif Supriyanto auraCMS 1.62 allow remote attackers to inject arbitrary web script or HTML via (1) the judul_artikel parameter in teman.php and (2) the title of an article sent to admin, which is displayed when unauthenticated users visit index.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
auraCMS | =1.62 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-3558 is considered a medium severity vulnerability due to the potential for cross-site scripting attacks.
To fix CVE-2006-3558, you should sanitize user inputs for the judul_artikel parameter in teman.php and other relevant fields to prevent XSS.
CVE-2006-3558 affects users of auraCMS version 1.62.
CVE-2006-3558 is classified as a cross-site scripting (XSS) vulnerability.
Yes, CVE-2006-3558 can be exploited remotely by attackers injecting malicious scripts.