Multiple cross-site scripting (XSS) vulnerabilities in IDE Group DVD Rental System (DRS) 5.1 before 20070801 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: it is not clear whether IDE Group updates all DRS installations in its role as an application service provider. If so, then this issue should not be included in CVE.
Link | Tags |
---|---|
http://secunia.com/advisories/26310 | third party advisory |
http://www.securityfocus.com/bid/25177 | vdb entry |
http://osvdb.org/39522 | vdb entry |
http://www.vupen.com/english/advisories/2007/2806 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/35768 | vdb entry |
http://archives.neohapsis.com/archives/fulldisclosure/2007-08/0020.html | mailing list |