Описание
Multiple cross-site scripting (XSS) vulnerabilities in Logaholic before 2.0 RC8 allow remote attackers to inject arbitrary web script or HTML via (1) the newconfname parameter to profiles.php or (2) the conf parameter to index.php.
Multiple cross-site scripting (XSS) vulnerabilities in Logaholic before 2.0 RC8 allow remote attackers to inject arbitrary web script or HTML via (1) the newconfname parameter to profiles.php or (2) the conf parameter to index.php.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2007-6560
- https://exchange.xforce.ibmcloud.com/vulnerabilities/39223
- http://osvdb.org/39792
- http://osvdb.org/39793
- http://secunia.com/advisories/28263
- http://securityreason.com/securityalert/3496
- http://www.securityfocus.com/archive/1/485480/100/0/threaded
- http://www.securityfocus.com/archive/1/490101/100/0/threaded
- http://www.securityfocus.com/bid/27003
Связанные уязвимости
nvd
больше 17 лет назад
Multiple cross-site scripting (XSS) vulnerabilities in Logaholic before 2.0 RC8 allow remote attackers to inject arbitrary web script or HTML via (1) the newconfname parameter to profiles.php or (2) the conf parameter to index.php.