ACS Blog 0.8/0.9/1.0/1.1 - 'Name' HTML Injection

Related Vulnerabilities: CVE-2005-0945  
Publish Date: 28 Mar 2005
Author: Dan Crowley


ACS Blog is affected by an HTML injection vulnerability.

The issue affects the 'Name' field and may be exploited to execute arbitrary HTML and script code in the browser of the user when the user views an affected Web page. 

Name: <script>alert("xss");</script>