CVE-2006-1818

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
18/04/2006
Last modified:
03/04/2025

Description

Multiple cross-site scripting (XSS) vulnerabilities in warforge.NEWS 1.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly including the (1) first_name and (2) last_name parameter in myaccounts.php. NOTE: portions of these details were obtained from third party sources instead of the original disclosure.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:the_war_forge:warforge.news:1.0:*:*:*:*:*:*:*