First published: Sun Dec 10 2006(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in the MyArticles module before 0.6 beta 1, for RunCMS, allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to (1) topics.php, (2) submit.php, and (3) class/calendar.class.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Myarticles Myarticles | <=0.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-6452 has a severity rating that indicates a moderate risk of cross-site scripting vulnerabilities allowing attackers to inject malicious scripts.
To fix CVE-2006-6452, upgrade the MyArticles module to a version beyond 0.6 beta 1 which addresses these XSS vulnerabilities.
CVE-2006-6452 affects all versions of the MyArticles module before 0.6 beta 1.
Attackers can perform cross-site scripting (XSS) attacks, injecting arbitrary web scripts or HTML into various parameters on affected pages.
The vulnerabilities in CVE-2006-6452 occur in the topics.php, submit.php, and class/calendar.class.php files of the MyArticles module.