2.6
CVSSv2

CVE-2006-3061

Published: 19/06/2006 Updated: 18/10/2018
CVSS v2 Base Score: 2.6 | Impact Score: 2.9 | Exploitability Score: 4.9
VMScore: 270
Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in 5 Star Review allow remote malicious users to inject arbitrary web script or HTML via the (1) sort parameter in index2.php, (2) item_id parameter in report.php, (3) search_term parameter (aka the "search box") in search_reviews.php, (4) the profile field in usercp/profile_edit1.php, and the (5) review field in review_form.php.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

review-script.com five star review script

Exploits

source: wwwsecurityfocuscom/bid/18390/info Five Star Review Script is prone to multiple input-validation vulnerabilities because the application fails to properly sanitize user-supplied input An attacker can exploit these issues to run arbitrary HTML and script code in the browser of a victim in the context of the affected site This ...
source: wwwsecurityfocuscom/bid/18390/info Five Star Review Script is prone to multiple input-validation vulnerabilities because the application fails to properly sanitize user-supplied input An attacker can exploit these issues to run arbitrary HTML and script code in the browser of a victim in the context of the affected site This ma ...