|
|

CVE Reference: CVE-2005-3552 |
|
| NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE. | |
|
Original Page at CVE MITRE: CVE-2005-3552 |
|
|
Description: Multiple cross-site scripting (XSS) vulnerabilities in PHPKIT 1.6.1 R2 and earlier allow remote attackers to inject arbitrary web script or HTML via multiple vectors in (1) login/profile.php, (2) login/userinfo.php, (3) admin/admin.php, (4) imcenter.php, and the (5) referer statistics, the (6) HTML title element and (7) logo alt attributes in forum postings, and the (8) Homepage field in the Guestbook. |
|
|
CVE Status: Candidate |
|
|
References: XF http://xforce.iss.net/xforce/xfdb/23003 http://xforce.iss.net/xforce/xfdb/23008 http://xforce.iss.net/xforce/xfdb/23007 http://xforce.iss.net/xforce/xfdb/23009 http://xforce.iss.net/xforce/xfdb/23004 http://xforce.iss.net/xforce/xfdb/23006 ST 1015167 SAID Secunia Advisory: SA17479 OSVDB 20559 20558 20557 20554 20555 20556 20553 MISC http://www.hardened-php.net/advisory_212005.80.html BUGTRAQ http://cert.uni-stuttgart.de/archive/bugtraq/2005/11/msg00110.html BID 15354 |
|
| Return to the previous page. |
Not a customer already?Learn more about how our market leading Vulnerability Management solutions can help you manage risk and ensure compliance. |