Description
Cross-site scripting (XSS) vulnerability in Web Content Management News System allows remote attackers to inject arbitrary web script or HTML via (1) the strRootpath parameter to validsession.php or (2) the strTable parameter to Admin/News/List.php.
Exploits (2)
References (5)
Core 5
Core References
Exploit x_refsource_misc
http://www.rgod.altervista.org/webc.html
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/16317
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/14464
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/21689
Exploit vdb-entry
x_refsource_sectrack
http://securitytracker.com/id?1014616
Scores
EPSS
0.0057
EPSS Percentile
68.6%
Details
Status
published
Products (1)
web_content_management/web_content_management_news_system
Published
Aug 07, 2005
Tracked Since
Feb 18, 2026