Provided and/or discovered by: 1) Reported by the vendor.
2) Keigo Yamazaki, LAC.
The vendor credits Scott Hughes and Martijn Brinkers.
3) The vendor credits Vicente Aguilera.
Changelog: 2006-02-24: Added additional cross-site scripting vulnerability.
2006-02-28: Updated "Description" and "Solution" sections.
2006-04-04: Added information provided by Keigo Yamazaki.
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.