6.8
CVSSv2

CVE-2006-5975

Published: 20/11/2006 Updated: 17/10/2018
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in comments.asp in BlogMe 3.0 allow remote malicious users to inject arbitrary web script or HTML via the (1) Name, (2) URL, or (3) Comments field.

Vulnerable Product Search on Vulmon Subscribe to Product

drumster blogme 3.0

Exploits

blogme v3 [admin login bypass & xss (post)] vendor site:wwwdrumsternet/ product:blogme v3 bug:login bypass & xss (post) risk:high admin login bypass : user : ' or '1' = '1 passwd: 1'='1' ro ' xss post : in: /commentsasp?blog=85 vulnerables fields: - Name - URL - Comments laurent gaffié & benjamin mossé s-a-p ...