Multiple cross-site scripting (XSS) vulnerabilities in Looking Glass 20040427 allow remote attackers to inject arbitrary web script or HTML via the (1) version[fullname], (2) version[homepage], or (3) version[no] parameter to footer.php, or the (4) version[fullname], (5) version[no], (6) version[author], (7) version[email] parameter to header.php.
Link | Tags |
---|---|
http://secunia.com/advisories/16607/ | third party advisory vendor advisory |
http://de-neef.net/articles.php?id=2&page=2 | |
http://rgod.altervista.org/lookingglass.html | exploit |
http://marc.info/?l=bugtraq&m=112516327607001&w=2 | mailing list |
https://exchange.xforce.ibmcloud.com/vulnerabilities/22044 | vdb entry |
http://www.securityfocus.com/bid/14680 | vdb entry exploit |