Multiple cross-site scripting (XSS) vulnerabilities in PHProjekt 5.2.0, when magic_quotes_gpc is disabled, allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors to the (1) Projects, (2) Contacts, (3) Helpdesk, (4) Search (only Gecko engine driven Browsers), and (5) Notes modules; the (6) Mail summary page; and unspecified other files.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
http://osvdb.org/34064 | vdb entry |
http://osvdb.org/34068 | vdb entry |
http://www.securityfocus.com/archive/1/462788/100/0/threaded | mailing list |
http://osvdb.org/34065 | vdb entry |
http://osvdb.org/34066 | vdb entry |
http://osvdb.org/34067 | vdb entry |
http://osvdb.org/34069 | vdb entry |
http://secunia.com/advisories/24509 | third party advisory |
http://www.securityfocus.com/bid/22957 | vdb entry |
http://www.phprojekt.com/index.php?name=News&file=article&sid=276 | patch vendor advisory broken link |
http://security.gentoo.org/glsa/glsa-200706-07.xml | third party advisory vendor advisory |
http://www.nruns.de/security_advisory_phprojekt_xss_and_filter_evasion.php | broken link vendor advisory |
http://securityreason.com/securityalert/2459 | third party advisory |
http://secunia.com/advisories/25748 | third party advisory |