Bugsalert.com
Security News about Viruses, Spyware,
Trojans, Malware, XSS attacks.

eTicket "Name" and "Subject" Script Insertion Vulnerabilities

BugsAlert Home > eTicket "Name" and "Subject" Script Insertion Vulnerabilities
 
 

Omer Singer has discovered two vulnerabilities in eTicket, which can be exploited by malicious people to conduct script insertion attacks.


Be sure to check if your system is missing security updates or have insecure applications installed:
http://secunia.com/software_inspector/

Feature Overview - The Secunia Software Inspector:
* Detects insecure versions of applications installed
* Verifies that all Microsoft patches are applied
* Assists you in updating your system and applications
* Runs through your browser. No installation or download is required.




Original Source: http://secunia.com/advisories/28331/

Learn more about eTicket "Name" and "Subject" Script Insertion Vulnerabilities
 
Tags: eticket subject script insertion vulnerabilities

Related Items

      Bugtraq: rPSA-2008-0082-1 espgs

      Bugtraq: Re: [IBM Datapower XS40] Denial of Service

      IBM Lotus Domino Web Server Unspecified Vulnerability

      Sweep Speex Header Processing Vulnerability

      FrSIRT - Masir Camp E-Shop Module "ordercode" SQL Injection Vulnerability

      CVE-2008-5496 (business_directory_script)

      Looking for

 

Pixel