Multiple cross-site scripting (XSS) vulnerabilities in livre_or.php in KorviBlog 1.3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) prenom, (2) emailFrom, or (3) body parameters.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/19943 | vdb entry |
http://secunia.com/advisories/21853 | third party advisory vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/28852 | vdb entry |
http://marc.info/?l=full-disclosure&m=115796637230932&w=2 | mailing list |