Bugsalert.com
Security News about Viruses, Spyware,
Trojans, Malware, XSS attacks.

CVE-2008-1969 (cezanne)

BugsAlert Home > CVE-2008-1969 (cezanne)
 
 

Multiple cross-site scripting (XSS) vulnerabilities in Cezanne 6.5.1 and 7 allow remote attackers to inject arbitrary web script or HTML via the (1) LookUPId and (2) CbFun parameters to (a) CFLookUP.asp; (3) TitleParms, (4) WidgetsHeights, (5) WidgetsLinks, and (6) WidgetsTitles parameters to (b) CznCommon/CznCustomContainer.asp, (7) CFTARGET parameter to (c) home.asp, (8) PersonOid parameter to (d) PeopleWeb/Cards/CVCard.asp, (9) DESTLINKOID and PersonOID parameters to (e) PeopleWeb/Cards/Pa...




Original Source: http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-1969

Learn more about CVE-2008-1969 (cezanne)
 
Tags: cve-2008-1969 cezanne

Related Items

      MSOCACHE/90000.../kb915865.exe=W32.dawin symptoms?

      CVE-2008-2152 (OpenOffice.org)

      Cheats Website "itemid" SQL Injection Vulnerability

      SuSE Security Update Fixes Samba "send_mailslot()" Vulnerability

      FrSIRT - Answers Module for Drupal Cross Site Scripting Vulnerability

      Review: 7 Linux/BSD Firewalls

      Bugtraq: webTA by kronos - XSS

 

Pixel