CVE-2011-1670

InTerra Blog Machine <1.84 - XSS

Title source: llm

Description

Cross-site scripting (XSS) vulnerability in actions/add.php in InTerra Blog Machine 1.84, and possibly earlier versions, allows remote attackers to inject arbitrary web script or HTML via the subject parameter to post_url/edit.

Exploits (2)

exploitdb WORKING POC VERIFIED
by High-Tech Bridge SA · textwebappsphp
https://www.exploit-db.com/exploits/35548
exploitdb WORKING POC VERIFIED
by High-Tech Bridge SA · textwebappsphp
https://www.exploit-db.com/exploits/17098

Scores

EPSS 0.0939
EPSS Percentile 92.7%

Classification

CWE
CWE-79
Status published

Affected Products (2)

a.kulikov/interra_blog_machine
n/a/n/a

Timeline

Published Apr 10, 2011
Tracked Since Feb 18, 2026