4.3
CVSSv2

CVE-2005-2721

Published: 30/08/2005 Updated: 11/07/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in (1) index.php or (2) admin.php in Foojan PHP Weblog allow remote malicious users to inject arbitrary web script or HTML via the Referer field in the HTTP header.

Vulnerable Product Search on Vulmon Subscribe to Product

foojan php weblog

Exploits

source: wwwsecurityfocuscom/bid/14658/info Foojan PHPWeblog is prone to an HTML injection vulnerability This is due to a lack of proper sanitization of user-supplied input Attacker-supplied HTML and script code would be executed in the context of the affected Web site, potentially allowing for theft of cookie-based authentication crede ...