Cross-site scripting (XSS) vulnerability in gui/errordocs/index.php in Virtual Hosting Control System (VHCS) 2.2.0 through 2.4.6.2 allows remote attackers to inject arbitrary web script or HTML via query strings that are included in an error message, as demonstrated using a parameter containing script.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/15538 | vdb entry exploit |
http://securityreason.com/securityalert/202 | third party advisory |
http://marc.info/?l=bugtraq&m=113269811630139&w=2 | mailing list |
http://moritz-naumann.com/adv/0006/vhcsxss/0006.txt | patch vendor advisory |
http://www.osvdb.org/21060 | vdb entry exploit |
https://exchange.xforce.ibmcloud.com/vulnerabilities/23209 | vdb entry |
http://secunia.com/advisories/17704/ | patch vendor advisory third party advisory |
http://lists.grok.org.uk/pipermail/full-disclosure/2005-November/039000.html | patch vendor advisory mailing list |