Multiple cross-site scripting (XSS) vulnerabilities in ProjectApp 3.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the keywords parameter to (1) forums.asp, (2) search_employees.asp, (3) cat.asp, and (4) links.asp; (5) projectid parameter to pmprojects.asp, (6) ret_page parameter to login.asp, and (7) skin_number parameter to default.asp.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
http://www.osvdb.org/21964 | vdb entry exploit |
http://www.vupen.com/english/advisories/2005/3040 | vdb entry vendor advisory |
http://www.osvdb.org/21965 | vdb entry exploit |
http://secunia.com/advisories/18199 | third party advisory vendor advisory |
http://www.osvdb.org/21966 | vdb entry exploit |
http://www.osvdb.org/21963 | vdb entry exploit |
http://pridels0.blogspot.com/2005/12/projectapp-mutliple-xss-vuln.html | |
http://www.osvdb.org/21962 | vdb entry exploit |
http://www.osvdb.org/21967 | vdb entry exploit |
http://www.securityfocus.com/bid/16011 | vdb entry exploit |
http://www.osvdb.org/21968 | vdb entry exploit |