Computer Security
[EN] securityvulns.ru
no-pyccku



CVECVE-2008-3101
StatusCandidate
DescriptionMultiple cross-site scripting (XSS) vulnerabilities in vtiger CRM 5.0.4 allow remote attackers to inject arbitrary web script or HTML via (1) the parenttab parameter in an index action to the Products module, as reachable through index.php; (2) the user_password parameter in an Authenticate action to the Users module, as reachable through index.php; or (3) the query_string parameter in a UnifiedSearch action to the Home module, as reachable through index.php.
PhaseAssigned (09.07.2008)
NVD:http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3101
ReferencesBID : 30951
 BUGTRAQ : 20080901 Multiple Cross Site Scripting (XSS) Vulnerabilities in vtigerCRM 5.0.4, CVE-2008-3101
 MISC : http://www.datensalat.eu/~fabian/cve/CVE-2008-3101...
 MISC : http://www.vtiger.de/vtiger-crm/downloads/patches....
 SECUNIA : 31679
 SREASON : 4208
 VUPEN : ADV-2008-2471
 XF : vtigercrm-index-xss(44792)
SecurityVulns:Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl)

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru
test server