Cross-site scripting (XSS) vulnerability in mnoGoSearch before 3.2.43 allows remote attackers to inject arbitrary web script or HTML via the t parameter in search.cgi, as reachable from search.htm-dist.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
http://secunia.com/advisories/27263 | third party advisory vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/37269 | vdb entry |
http://osvdb.org/37929 | vdb entry |
http://www.mnogosearch.org/doc/msearch-changelog.html | |
http://www.securityfocus.com/bid/26114 | vdb entry |