CVE-2008-6631
EUVD-2008-659307.04.2009, 14:17
Multiple cross-site scripting (XSS) vulnerabilities in index.php in BlogPHP 2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) user parameter in a sendmessage action and the (2) username parameter when registering a new user, different vectors than CVE-2008-0679.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| blogphp | blogphp | 2.0 |
𝑥
= Vulnerable software versions
References