Cross-site scripting (XSS) vulnerability in index.php in MobeScripts Mobile Space Community 2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) browse parameter, which is not filtered in the resulting error message, and multiple unspecified input fields, including those involved when (2) updating a profile, (3) posting comments or entries in a blog, (4) uploading files, (5) picture captions, and (6) sending a private message (PM).
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2006-06-23T00:00:00

Updated: 2017-07-19T15:57:01

Reserved: 2006-06-22T00:00:00


Link: CVE-2006-3183

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2006-06-23T00:02:00.000

Modified: 2017-07-20T01:32:07.117


Link: CVE-2006-3183

JSON object: View

cve-icon Redhat Information

No data.