Multiple cross-site scripting (XSS) vulnerabilities in FarsiNews 2.5.3 Pro and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) month and (2) year parameters in (a) index.php, and the (3) mod parameter in (b) admin.php.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2006-04-29T10:00:00

Updated: 2018-10-18T14:57:01

Reserved: 2006-04-28T00:00:00


Link: CVE-2006-2084

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2006-04-29T10:02:00.000

Modified: 2018-10-18T16:38:05.177


Link: CVE-2006-2084

JSON object: View

cve-icon Redhat Information

No data.

CWE