Description: A vulnerability has been identified in H-Sphere which allows malicious people to conduct Cross Site Scripting.
The problem is that the "template_name" and "ftemplate" parameter isn't verified before it is returned to the user. When an invalid template is requested, the name of the template will be returned without further validation. This allows malicious people to conduct Cross Site Scripting.
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.