Multiple cross-site scripting (XSS) vulnerabilities in eyeOS before 0.9.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors involving (1) eyeNav and (2) system/baixar.php.
Link | Tags |
---|---|
http://secunia.com/advisories/22117 | third party advisory patch vendor advisory |
http://www.securityfocus.com/bid/20213 | vdb entry patch |
http://eyeos.blogspot.com/2006/09/eyeos-091-released.html | patch |
https://exchange.xforce.ibmcloud.com/vulnerabilities/29190 | vdb entry |
http://sourceforge.net/project/shownotes.php?group_id=145027&release_id=450490 | patch |
http://www.vupen.com/english/advisories/2006/3780 | vdb entry |