Cross-site scripting (XSS) vulnerability in index.php in dl Download Ticket Service before 0.7 allows remote attackers to inject arbitrary web script or HTML via the t parameter, related to an invalid ticket ID. NOTE: some of these details are obtained from third party information.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
http://secunia.com/advisories/38898 | third party advisory vendor advisory |
http://www.securityfocus.com/bid/38700 | vdb entry patch |
http://freshmeat.net/projects/dl-ticket-service | patch |
http://osvdb.org/62884 | vdb entry |
http://article.gmane.org/gmane.comp.web.dl-ticket-service.general/33 | mailing list patch |