Multiple cross-site scripting (XSS) vulnerabilities in OrbitHYIP 2.0 and earlier allow remote attackers to inject arbitrary web script via the (1) referral parameter to signup.php or (2) id parameter to members.php.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: mitre
Published: 2006-05-02T10:00:00
Updated: 2024-08-07T17:35:31.503Z
Reserved: 2006-05-01T00:00:00
Link: CVE-2006-2140

No data.

Status : Modified
Published: 2006-05-02T10:02:00.000
Modified: 2024-11-21T00:10:38.900
Link: CVE-2006-2140

No data.