1 results (0.001 seconds)

CVSS: 6.1EPSS: 0%CPEs: 4EXPL: 3

26 Oct 2006 — Multiple cross-site scripting (XSS) vulnerabilities in Boesch SimpNews before 2.34.01 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to (1) admin/index.php, (2) admin/pwlost.php, and unspecified other files. NOTE: the provenance of this information is unknown; the details are obtained from third party information. Vulnerabilidades de cruce de sitios en scripts (XSS) en Boesch SimpNews versiones anteriores a 2.34.01 permiten a atacantes remotos inyectar scripts WEB o... • https://www.exploit-db.com/exploits/28858 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •