Multiple cross-site scripting (XSS) vulnerabilities in post.asp in MaxWebPortal 1.3.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) mod, (2) M, or (3) type parameter.
Link | Tags |
---|---|
http://marc.info/?l=bugtraq&m=111584883727605&w=2 | mailing list |
https://exchange.xforce.ibmcloud.com/vulnerabilities/20560 | vdb entry |
http://www.osvdb.org/16501 | vdb entry |
http://www.hackerscenter.com/archive/view.asp?id=2542 | vendor advisory |
http://secunia.com/advisories/15329 | patch vendor advisory third party advisory exploit |
http://www.securityfocus.com/bid/13601 | vdb entry vendor advisory |