Multiple cross-site scripting vulnerabilities in castnewPost.asp in Liberum Help Desk 0.97.3 allow remote attackers to inject arbitrary web script or HTML via the (1) Email, (2) Title, or (3) Description fields.
References
Link | Resource |
---|---|
http://echo.or.id/adv/adv14-theday-2005.txt | Exploit Vendor Advisory |
http://marc.info/?l=bugtraq&m=111773586701991&w=2 | |
http://echo.or.id/adv/adv14-theday-2005.txt | Exploit Vendor Advisory |
http://marc.info/?l=bugtraq&m=111773586701991&w=2 |
Configurations
History
20 Nov 2024, 23:58
Type | Values Removed | Values Added |
---|---|---|
References | () http://echo.or.id/adv/adv14-theday-2005.txt - Exploit, Vendor Advisory | |
References | () http://marc.info/?l=bugtraq&m=111773586701991&w=2 - |
Information
Published : 2005-06-02 04:00
Updated : 2025-04-03 01:03
NVD link : CVE-2005-1838
Mitre link : CVE-2005-1838
CVE.ORG link : CVE-2005-1838
JSON object : View
Products Affected
liberum
- liberum_help_desk
CWE