CVE-2010-2796
CVE-2010-2796
Cross-site scripting (XSS) vulnerability in phpCAS before 1.1.2, when proxy mode is enabled, allows remote attackers to inject arbitrary web script or HTML via a callback URL.
Productos afectados
n/a · n/a¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →Referencias
http://lists.fedoraproject.org/pipermail/package-announce/2010-August/046576.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-August/046584.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-November/050415.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-November/050428.htmlhttp://secunia.com/advisories/40845http://secunia.com/advisories/41240http://secunia.com/advisories/42149http://secunia.com/advisories/42184http://secunia.com/advisories/43427https://exchange.xforce.ibmcloud.com/vulnerabilities/60895https://forge.indepnet.net/projects/glpi/repository/revisions/12601https://issues.jasig.org/browse/PHPCAS-67