Description
WeBid 1.2.2 has reflected XSS via the id parameter to admin/deletenews.php, admin/editbannersuser.php, admin/editfaqscategory.php, or admin/excludeuser.php, or the offset parameter to admin/edituser.php.
Remediation
References
Related Vulnerabilities
WordPress Plugin WordPress Landing Pages Multiple Unspecified Vulnerabilities (1.7.8)
Moodle Other Vulnerability (CVE-2006-4938)
Joomla! Core Directory Traversal (2.5.0 - 3.9.20)
WordPress Plugin Pinpoint Booking System-#1 WordPress Booking SQL Injection (2.0)
PostgreSQL Permissions, Privileges, and Access Controls Vulnerability (CVE-2007-6600)