Bugsalert.com
Security News about Viruses, Spyware,
Trojans, Malware, XSS attacks.

CVE-2008-2196 (LifeType)

BugsAlert Home > CVE-2008-2196 (LifeType)
 
 

Cross-site scripting (XSS) vulnerability in admin.php in LifeType 1.2.8 allows remote attackers to inject arbitrary web script or HTML via the newBlogUserName parameter in an addBlogUser action, a different vector than CVE-2008-2178.




Original Source: http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-2196

Learn more about CVE-2008-2196 (LifeType)
 
Tags: cve-2008-2196 lifetype

Related Items

      CVE-2008-2790 (easyTrade)

      CVE-2008-1897 (Open Source, Asterisk Business Edition, AsteriskNOW, Asterisk Appliance Developer...)

      activePDF Server Packet Handling Buffer Overflow Vulnerability

      CVE-2008-3239 (phpizabi)

      FrSIRT - RoomPHPlanning SQL Injection and Admin Account Creation Issues

      XSS in PHP-Nuke (eWeather module)

      CVE-2008-0416 (Firefox)

 

Pixel