First published: Thu Jul 27 2006(Updated: )
CRLF injection vulnerability in (1) index.php and (2) admin.php in myWebland MyBloggie 2.1.3 allows remote attackers to hijack sessions and conduct cross-site scripting (XSS) attacks via a cookie.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
myWebland myBloggie | =2.1.3_beta | |
myWebland myBloggie | =2.1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-3903 is considered a high severity vulnerability due to its potential to allow session hijacking and XSS attacks.
To fix CVE-2006-3903, ensure that input received in index.php and admin.php is properly sanitized to prevent CRLF injection.
CVE-2006-3903 affects myWebland MyBloggie versions 2.1.3 and 2.1.3_beta.
Yes, CVE-2006-3903 can be exploited to conduct cross-site scripting (XSS) attacks.
Exploiting CVE-2006-3903 can result in session hijacking, allowing attackers to impersonate users.