[] NeoSense

e107 0.7.5 - 'Subject' HTML Injection

Author: EllipSiS Security
type: webapps
platform: php
port: 
date_added: 2006-06-21 
date_updated: 2013-09-04 
verified: 1 
codes: CVE-2006-3259;OSVDB-26685 
tags: 
aliases:  
screenshot_url:  
application_url: 

source: https://www.securityfocus.com/bid/18560/info

The e107 CMS is prone to an HTML-injection vulnerability.

An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site when the inserted data is viewed.

In Submit comment:
Subject: '><script>alert(/XSS/)</script>