CVE-2005-3552
CVE-2005-3552
Multiple cross-site scripting (XSS) vulnerabilities in PHPKIT 1.6.1 R2 and earlier allow remote attackers to inject arbitrary web script or HTML via multiple vectors in (1) login/profile.php, (2) login/userinfo.php, (3) admin/admin.php, (4) imcenter.php, and the (5) referer statistics, the (6) HTML title element and (7) logo alt attributes in forum postings, and the (8) Homepage field in the Guestbook.
Produtos afetados
n/a · n/aQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →Referências
http://cert.uni-stuttgart.de/archive/bugtraq/2005/11/msg00110.htmlhttp://secunia.com/advisories/17479http://securitytracker.com/id?1015167https://exchange.xforce.ibmcloud.com/vulnerabilities/23003https://exchange.xforce.ibmcloud.com/vulnerabilities/23004https://exchange.xforce.ibmcloud.com/vulnerabilities/23006https://exchange.xforce.ibmcloud.com/vulnerabilities/23007https://exchange.xforce.ibmcloud.com/vulnerabilities/23008https://exchange.xforce.ibmcloud.com/vulnerabilities/23009http://www.hardened-php.net/advisory_212005.80.htmlhttp://www.osvdb.org/20553http://www.osvdb.org/20554