CVE-2006-5827 - Lactic Dugong
Description
Multiple cross-site scripting (XSS) vulnerabilities in index.php in phpComasy CMS 0.7.9pre and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) username or (2) password parameters.
Reference
http://www.securityfocus.com/archive/1/450712 http://www.majorsecurity.de/index_2.php?major_rls=major_rls32 http://www.securityfocus.com/bid/20938 http://secunia.com/advisories/22760 http://securityreason.com/securityalert/1843 https://exchange.xforce.ibmcloud.com/vulnerabilities/30053