CVE-2004-2246 Information

Description

Cross-site scripting (XSS) vulnerability in Goollery before 0.04b allows remote attackers to inject arbitrary HTML or web script via the conversation_id parameter to viewpic.php.

Reference

http://www.osvdb.org/11624 http://www.osvdb.org/ref/11/11624-goollery-viewpic.txt

Share on: