Multiple cross-site scripting (XSS) vulnerabilities in Buddy Zone 1.0.1 allow remote attackers to inject arbitrary HTML and web script via the (1) cat_id parameter to (a) view_classifieds.php; (2) id parameter in (b) view_ad.php; (3) event_id parameter in (c) view_event.php, (d) delete_event.php, and (e) edit_event.php; and (4) group_id in (f) view_group.php.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2006-07-10T22:00:00
Updated: 2024-08-07T18:30:33.905Z
Reserved: 2006-07-10T00:00:00
Link: CVE-2006-3494
Vulnrichment
No data.
NVD
Status : Modified
Published: 2006-07-10T22:05:00.000
Modified: 2024-11-21T00:13:45.050
Link: CVE-2006-3494
Redhat
No data.