CVE-2006-6019: XSS
Published Nov 21, 2006
·Updated
Cross-site scripting (XSS) vulnerability in extensions/googiespell/googlespellproxy.php in Bill Roberts Bloo 1.0 allows remote attackers to inject arbitrary web script or HTML via the lang parameter.
Affected Software
1 affected component
Bloo Bloo=1.0
Event History
Nov 21, 2006
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Data Sourced
via NVD·11:07 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2006-6019?
CVE-2006-6019 is considered a moderate severity vulnerability due to potential cross-site scripting risks.
2
How can I fix CVE-2006-6019?
To fix CVE-2006-6019, sanitize and validate the input for the lang parameter before processing it.
3
What type of vulnerability is CVE-2006-6019?
CVE-2006-6019 is a cross-site scripting (XSS) vulnerability that enables injection of arbitrary web scripts.
4
Who is affected by CVE-2006-6019?
CVE-2006-6019 affects users of Bill Roberts Bloo version 1.0 that utilize the googlespell_proxy.php extension.
5
What could be the impact of CVE-2006-6019?
The impact of CVE-2006-6019 could allow remote attackers to execute malicious scripts in users' browsers.