SecurityAlert : 1028 CVE : CVE-2006-2820 SecurityRisk : Low (About) Remote Exploit : Yes Local Exploit : No Exploit Available : Yes Credit : luny youfucktard com Published : 06.06.2006
Affected Software :
Weblog Oggi v1.0
Advisory Content :
Weblog Oggi v1.0
Homepage:
http://www.hotwebscripts.com/index.php
User input isn't sanatized before being dynamically generated. For proof of
concept just put <IMG SRC="javascript:alert('XSS');"> in as a comment
Feedback :
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.