Multiple cross-site scripting (XSS) vulnerabilities in add_comment.php in Wheatblog (wB) allow remote attackers to inject arbitrary web script or HTML via the (1) Name, (2) WWW, and (3) Comment fields. NOTE: this issue may overlap CVE-2006-5195.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Wheatblog | Wheatblog | * | 1.1 (including) |