Multiple cross-site scripting (XSS) vulnerabilities in activeWeb contentserver before 5.6.2964 allow remote attackers to inject arbitrary web script or HTML via the msg parameter to (1) errors/rights.asp or (2) errors/transaction.asp, or (3) the name of a MIME type (mimetype).
Link | Tags |
---|---|
http://www.securityfocus.com/bid/24896 | vdb entry |
http://www.osvdb.org/36259 | vdb entry |
http://www.securityfocus.com/archive/1/473631/100/0/threaded | mailing list |
http://www.osvdb.org/36261 | vdb entry |
http://www.securityfocus.com/bid/24895 | vdb entry exploit |
https://exchange.xforce.ibmcloud.com/vulnerabilities/35389 | vdb entry |
http://www.osvdb.org/36260 | vdb entry |
http://www.redteam-pentesting.de/advisories/rt-sa-2007-005.php | exploit patch vendor advisory |
http://secunia.com/advisories/26063 | third party advisory |