Multiple cross-site scripting (XSS) vulnerabilities in Netjuke 1.0-rc2 allow remote attackers to inject arbitrary web script or HTML via (1) the val parameter to alphabet.php in an alpha.albums action, or the PATH_INFO to (2) random.php or (3) admin/hidden.php.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
http://osvdb.org/38402 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/36517 | vdb entry |
http://osvdb.org/38403 | vdb entry |
http://www.securityfocus.com/archive/1/478871/100/0/threaded | mailing list |
http://osvdb.org/38404 | vdb entry |
http://securityreason.com/securityalert/3110 | third party advisory |
http://www.securityfocus.com/bid/25599 | vdb entry exploit |