Cross-site scripting (XSS) vulnerability in index.php in Speedywiki 2.0 allows remote attackers to inject arbitrary web script or HTML via the showRevisions parameter.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
http://marc.info/?l=bugtraq&m=116302805802656&w=2 | mailing list |
https://exchange.xforce.ibmcloud.com/vulnerabilities/30132 | vdb entry |
http://secunia.com/advisories/22788 | third party advisory vendor advisory |
http://www.vupen.com/english/advisories/2006/4421 | vdb entry not applicable |
http://www.securityfocus.com/bid/20976 | exploit vdb entry third party advisory |
http://s-a-p.ca/index.php?page=OurAdvisories&id=9 | url repurposed broken link |
http://securitytracker.com/id?1017201 | vdb entry third party advisory |