Multiple cross-site scripting (XSS) vulnerabilities in OrbitHYIP 2.0 and earlier allow remote attackers to inject arbitrary web script via the (1) referral parameter to signup.php or (2) id parameter to members.php.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: mitre
Published: 2006-05-02T10:00:00
Updated: 2024-08-07T17:35:31.503Z
Reserved: 2006-05-01T00:00:00
Link: CVE-2006-2140

No data.

Status : Deferred
Published: 2006-05-02T10:02:00.000
Modified: 2025-04-03T01:03:51.193
Link: CVE-2006-2140

No data.