Heap
25-07-08, 22:05
Multiple cross-site scripting (XSS) vulnerabilities in BilboBlog 0.2.1 allow remote authenticated administrators to inject arbitrary web script or HTML via the (1) content parameter to admin/update.php, related to conflicting code in widget.php; and allow remote attackers to inject arbitrary web script or HTML via the (2) titleId parameter to head.php, reachable through index.php; the (3) t_lang[lang_copyright] parameter to footer.php; the (4) content parameter to the default URI under admin/...
More... (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3301)
More... (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3301)