Multiple cross-site scripting (XSS) vulnerabilities in aasi media Net Clubs Pro 4.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) onuser, (2) pass, (3) chatsys, (4) room, (5) username, and (6) to parameters in (a) sendim.cgi; the (7) username parameter in (b) imessage.cgi; the (8) password parameter in (c) login.cgi; and the (9) cat_id parameter in (d) viewcat.cgi.
References
Configurations
History
No history.
Information
Published : 2006-04-21 10:02
Updated : 2017-07-20 01:31
NVD link : CVE-2006-1965
Mitre link : CVE-2006-1965
CVE.ORG link : CVE-2006-1965
JSON object : View
Products Affected
aasi_media
- net_clubs_pro
CWE