Published: 01/03/2011 Updated: 22/09/2011
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in BLOG:CMS 4.2.1.e, and possibly earlier, allow remote malicious users to inject arbitrary web script or HTML via the (1) body parameter to action.php and the (2) amount and (3) action parameters to admin/index.php.

Affected Products

Vendor Product Versions


Vulnerability ID: HTB22727 Reference: wwwhtbridgech/advisory/xsrf_csrf_in_blogcmshtml Product: BLOG:CMS Vendor: Radek Hulán ( blogcmscom/ ) Vulnerable Version: 421e and probably prior versions Vendor Notification: 30 November 2010 Vulnerability Type: CSRF (Cross-Site Request Forgery) Status: Not Fixed, Vendor Alerted Risk le ...