Cross-site scripting (XSS) vulnerability in index.php AlstraSoft E-Friends allows remote attackers to inject arbitrary web script or HTML via the p_id parameter in a people_card action. NOTE: this might overlap CVE-2006-2564.
Link | Tags |
---|---|
http://lostmon.blogspot.com/2007/07/alstrasoft-multiple-products-multiple.html | exploit |
http://osvdb.org/37266 | vdb entry |