CVE-2005-1975 Information

Description

Multiple cross-site scripting (XSS) vulnerabilities in Annuaire 1Two 1.1 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the id parameter to index.php or the (2) site_id (3) nom (4) email or (5) commentaire parameters in commentaires.php.

Reference

http://secunia.com/advisories/15708 http://securitytracker.com/id?1014187 http://www.hackisknowledge.org/Advisories/Annuaire201Two20v1.0/Annuaire201Two20v1.0.html http://www.securityfocus.com/bid/13612 http://www.securityfocus.com/bid/13960 http://www.securityfocus.com/bid/13961

Share on: