Multiple cross-site scripting (XSS) vulnerabilities in (1) dsp_main.php and (2) dsp_task_editor.php in SamTodo 1.1 allow remote attackers to inject arbitrary web script or HTML via the (a) tid parameter in a main.taskeditor edit action, and the (b) completed parameter in a main.default action, to index.php.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/29568 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/42868 | vdb entry |
http://secunia.com/advisories/30557 | third party advisory vendor advisory |
http://www.davidsopas.com/soapbox/samtodo.txt | |
http://www.securityfocus.com/bid/29569 | vdb entry |