Multiple cross-site scripting (XSS) vulnerabilities in VBzoom allow remote attackers to inject arbitrary web script and HTML via the (1) UserName parameter to profile.php or (2) UserID parameter to login.php.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/14423 | vdb entry |
http://www.securityfocus.com/archive/1/426874/100/0/threaded | mailing list |
http://secunia.com/advisories/16220 | third party advisory |
http://www.osvdb.org/18662 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/21680 | vdb entry |
http://www.osvdb.org/18663 | vdb entry |
http://marc.info/?l=bugtraq&m=112300586019568&w=2 | mailing list |
http://securitytracker.com/id?1014614 | vdb entry |