Bugsalert.com
Security News about Viruses, Spyware,
Trojans, Malware, XSS attacks.

CVE-2007-6173 (Liferay Enterprise Portal)

BugsAlert Home > CVE-2007-6173 (Liferay Enterprise Portal)
 
 

Cross-site scripting (XSS) vulnerability in c/portal/login in Liferay Enterprise Portal 4.3.1 allows remote attackers to inject arbitrary web script or HTML via the emailAddress parameter in a Send New Password action, a different vector than CVE-2007-6055. NOTE: some of these details are obtained from third party information.




Original Source: http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-6173

Learn more about CVE-2007-6173 (Liferay Enterprise Portal)
 
Tags: cve-2007-6173 liferay enterprise portal

Related Items

      CVE-2008-3259 (OpenSSH)

      MS08-034 ? Important: Vulnerability in WINS Could Allow Elevation of Privilege (948745) - Version:1.1

      Fedora update for wordpress

      CVE-2008-2311 (Mac OS X Server)

      SuSE Security Update Fixes Kernel Buffer Overflow and Denial of Service

      ShopCartDx "pid" SQL Injection Vulnerability

      Bugtraq: Re: [funsec] facebook messages worm

 

Pixel