Cross-site scripting (XSS) vulnerability in do_search.php in PROPS 0.6.1 allows remote attackers to inject arbitrary HTML or web script via the search_string parameter.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/16035 | vdb entry |
http://www.securityfocus.com/bid/10258 | vdb entry patch vendor advisory |
http://sourceforge.net/project/shownotes.php?group_id=29581&release_id=234433 | patch |
http://marc.info/?l=bugtraq&m=108342671616155&w=2 | mailing list |