Bugsalert.com
Security News about Viruses, Spyware,
Trojans, Malware, XSS attacks.

CVE-2008-0180 (Liferay Enterprise Portal)

BugsAlert Home > CVE-2008-0180 (Liferay Enterprise Portal)
 
 

Cross-site scripting (XSS) vulnerability in themes/_unstyled/templates/init.vm in Liferay Portal 4.3.6 allows remote authenticated users to inject arbitrary web script or HTML via the Greeting field in a User Profile.




Original Source: http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-0180

Learn more about CVE-2008-0180 (Liferay Enterprise Portal)
 
Tags: cve-2008-0180 liferay enterprise portal

Related Items

      Vuln: Apache Tomcat Mod_JK.SO Arbitrary Code Execution Vulnerability

      FrSIRT - Apple Mac OS X Code Execution and Security Bypass Vulnerabilities

      CVE-2007-6177 (PHP-Con)

      VBS_RUNAUTO.R

      FrSIRT - Gentoo Security Update Fixes HAVP Denial of Service Vulnerability

      CVE-2008-5416 (sql_server)

      Vuln: bzip2 Remote Denial of Service Vulnerability

 

Pixel