Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2006-1205

Quick assessment

Affected
n/a n/a
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

myWebland myBloggie 2.1.3 beta及其早期版本中存在多个跨站脚本攻击(XSS)漏洞,远程攻击者可通过以下途径注入任意Web脚本或HTML:在(a) delcomment.php中的(1) confirmredirect和(2) post_id参数,当mode=delcom 时,可从index.php中访问;和在(b) upload.php中的(3) del和(4) message参数,在(c) addcat.php,(d) edituser.php,(e) adduser.php

AI Predicted 6.1 Difficulty: Easy EPSS 2.86% · P86
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2006-1205

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
Multiple cross-site scripting (XSS) vulnerabilities in myWebland myBloggie 2.1.3 beta and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) confirmredirect and (2) post_id parameters in (a) delcomment.php, as reachable when mode=delcom from index.php; and the (3) del and (4) message parameters in (b) upload.php, the (5) errormsg parameter in (c) addcat.php, (d) edituser.php, (e) adduser.php, and (f) editcat.php, the (6) trackback_url parameter in (g) add.php, (7) id parameter in (h) deluser.php, (8) cat_id parameter in (i) delcat.php, and (9) post_id parameter in (j) del.php, as reachable from admin.php.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
MyBloggie多个跨站脚本攻击漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
myWebland myBloggie 2.1.3 beta及其早期版本中存在多个跨站脚本攻击(XSS)漏洞,远程攻击者可通过以下途径注入任意Web脚本或HTML:在(a) delcomment.php中的(1) confirmredirect和(2) post_id参数,当mode=delcom 时,可从index.php中访问;和在(b) upload.php中的(3) del和(4) message参数,在(c) addcat.php,(d) edituser.php,(e) adduser.php
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
- n/a n/a -

II. Public POCs for CVE-2006-1205

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2006-1205

登录查看更多情报信息。

Vendor Advisories for CVE-2006-1205 (10)

Other References for CVE-2006-1205 (1)

Same Patch Batch · n/a · 2006-03-14 · 50 CVEs total

CVE-2006-1199 Link Bank 'Iframe.PHP'跨站脚本攻击漏洞
CVE-2006-1206 Matt Johnston Dropbear SSH 远程拒绝服务漏洞
CVE-2006-1210 Micromuse Netcool/NeuSecure网站NS账户口令泄露漏洞
CVE-2006-1211 IBM Tivoli Micromuse Netcool/NeuSecure ns数据库账户安全绕过漏洞
CVE-2006-1212 Core CoreNews ‘Index.PHP’远程代码执行漏洞
CVE-2006-1213 JiRo's Banner ‘Addadmin.ASP’授权绕过漏洞
CVE-2006-1214 UnrealIRCd远程拒绝服务漏洞
CVE-2006-1209 PHP高级传输管理器 users/[USERNAME] 文件敏感信息泄露漏洞
CVE-2006-1201 phpBannerExchange 'resetpw.php'输入验证错误漏洞
CVE-2006-1200 Link Bank ‘add_link.txt’直接静态代码注入漏洞
CVE-2006-1202 TextfileBB多个跨站脚本攻击漏洞
CVE-2006-1198 Comvigo IM锁2006不安全口令存储漏洞
CVE-2006-1220 Apple Mac OS X Kernel MACH_MSG_SEND本地堆溢出漏洞
CVE-2006-1219 Gallery多个本地文件包含漏洞
CVE-2006-1218 Novell BorderManager远程拒绝服务漏洞
CVE-2006-1217 DSPoll PollID SQL注入漏洞
CVE-2006-1216 RunCMS 'Bigshow.PHP'跨站脚本攻击漏洞
CVE-2006-1215 Woltlab Burning Board Misc.PHP跨站脚本攻击漏洞
CVE-2006-0457 Linux Kernel安全键函数本地向用户复制比赛漏洞
CVE-2006-1224 GuppY 'Dwnld.PHP'远程目录遍历漏洞

Showing top 20 of 50 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2006-1205

No comments yet


Leave a comment