Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2008-7092
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2008-7092

Description:
Multiple cross-site scripting (XSS) vulnerabilities in Unica Affinium Campaign 7.2.1.0.55 allow remote attackers to inject arbitrary web script or HTML via a Javascript event in the (1) url, (2) PageName, and (3) title parameters in a CustomBookMarkLink action to Campaign/Campaign; (4) a Javascript event in the displayIcon parameter to Campaign/updateOfferTemplateSubmit.do (aka the templates web page); (5) crafted input to Campaign/CampaignListener (aka the listener server), which is not properly handled when displaying the status log; and (6) id parameter to Campaign/campaignDetails.do, (7) id parameter to Campaign/offerDetails.do, (8) function parameter to Campaign/Campaign, (9) sessionID parameter to Campaign/runAllFlowchart.do, (10) id parameter in an edit action to Campaign/updateOfferTemplatePage.do, (11) Frame parameter in a LoadFrame action to Campaign/Campaign, (12) affiniumUserName parameter to manager/jsp/test.jsp, (13) affiniumUserName parameter to Campaign/main.do, and possibly other vectors.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/44073
  http://xforce.iss.net/xforce/xfdb/44072
  http://xforce.iss.net/xforce/xfdb/44074

SAID
  Secunia Advisory: SA31280

OSVDB
  47520
  47521
  47522
  47523
  47524
  47525
  47526
  47528
  47530

MISC
  http://www.portcullis.co.uk/286.php
  http://www.portcullis.co.uk/288.php
  http://www.portcullis.co.uk/289.php
  http://www.portcullis.co.uk/290.php

BID
  30433


Return to the previous page.