Multiple cross-site scripting (XSS) vulnerabilities in FarsiNews 2.5.3 Pro and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) month and (2) year parameters in (a) index.php, and the (3) mod parameter in (b) admin.php.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: mitre
Published: 2006-04-29T10:00:00
Updated: 2024-08-07T17:35:31.275Z
Reserved: 2006-04-28T00:00:00
Link: CVE-2006-2084

No data.

Status : Modified
Published: 2006-04-29T10:02:00.000
Modified: 2024-11-21T00:10:31.167
Link: CVE-2006-2084

No data.