PublicDate: 2006-11-04 01:07:00 UTC Candidate: CVE-2006-5703 References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5703 Description: Cross-site scripting (XSS) vulnerability in tiki-featured_link.php in Tikiwiki 1.9.5 allows remote attackers to inject arbitrary web script or HTML via a url parameter that evades filtering, as demonstrated by a parameter value containing malformed, nested SCRIPT elements. Ubuntu-Description: Notes: Priority: untriaged Discovered-by: Assigned-to: CVSS: Bugs: dapper_tikiwiki: DNE edgy_tikiwiki: DNE feisty_tikiwiki: released (1.9.7+dfsg-1ubuntu1) devel_tikiwiki: released (1.9.7+dfsg-1ubuntu1) upstream_tikiwiki: needs-triage