Bugsalert.com
Security News about Viruses, Spyware,
Trojans, Malware, XSS attacks.

CVE-2008-2117 (Project Alumni)

BugsAlert Home > CVE-2008-2117 (Project Alumni)
 
 

Cross-site scripting (XSS) vulnerability in pages/news.page.inc in Project Alumni 1.0.9 allows remote attackers to inject arbitrary web script or HTML via the year parameter in a news action to index.php, a different vector than CVE-2007-6126.




Original Source: http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-2117

Learn more about CVE-2008-2117 (Project Alumni)
 
Tags: cve-2008-2117 project alumni

Related Items

      CVE-2008-3760 (Vanilla)

      TROJ_DLOADER.QIU

      CVE-2008-2484 (xomol_cms)

      LineShout Two Script Insertion Vulnerabilities

      Bugtraq: [ MDVSA-2008:115 ] - Updated x11-server packages fix several vulnerabilities

      CVE-2008-3218 (Drupal)

      FrSIRT - rPath Linux Security Update Fixes MySQL yaSSL Multiple Vulnerabilities

 

Pixel