SecurityAlert : 1170 CVE : CVE-2006-3299 SecurityRisk : Low (About) Remote Exploit : Yes Local Exploit : No Exploit Available : Yes Credit : luny youfucktard com Published : 01.07.2006
Affected Software :
Usenet Script v0.5
Advisory Content :
Usenet Script v0.5
Homepage:
http://www.metalhead.ws/usenet
Description:
"Those scripts allow you to mirror a Newsgroup in an SQL database. The
development database was Postgresql, but it uses dbx and should therefore
be able to work with other database systems, too. Furthermore, a frontend
is provided."
Affected files:
index.php
------------------------------------
XSS vuln via index.php on group var:
Data isnt properly sanatized before being generated.
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.