Multiple cross-site scripting (XSS) vulnerabilities in index.php in MercuryBoard 1.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) s, (2) l, (3) a, (4) t, (5) to, or (6) re parameters.
Link | Tags |
---|---|
http://marc.info/?l=bugtraq&m=110661795632354&w=2 | mailing list |
https://exchange.xforce.ibmcloud.com/vulnerabilities/19050 | vdb entry |
http://www.securityfocus.com/bid/12359 | vdb entry patch vendor advisory |