RSS   Vulnerabilities for 'Ringlink'   RSS

2006-06-12
 
CVE-2006-2991

CWE-Other
 

 
Multiple cross-site scripting (XSS) vulnerabilities in Ringlink 3.2 allow remote attackers to inject arbitrary web script or HTML via a JavaScript URI in the SRC attribute of an IMG element, and possibly other manipulations, in the ringid parameter in (1) next.cgi, (2) stats.cgi, or (3) list.cgi.

 


Copyright 2024, cxsecurity.com

 

Back to Top