Cross-site scripting (XSS) vulnerability in the skinning feature in SiteKiosk before 6.5.150 allows local users to bypass security protections and inject arbitrary web script or HTML via an ABOUT: URI, which is displayed in the title bar of the browser.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2006-12-14 00:28
Updated : 2024-02-28 11:01
NVD link : CVE-2006-6509
Mitre link : CVE-2006-6509
CVE.ORG link : CVE-2006-6509
JSON object : View
Products Affected
sitekiosk
- sitekiosk
CWE