CVE-2005-2853 Information

Description

Multiple cross-site scripting (XSS) vulnerabilities in GuppY 4.5.3a and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the pg parameter to printfaq.php or the (2) Referer or (3) User-Agent HTTP headers which are not properly handled by error.php.

Reference

http://secunia.com/advisories/16707 http://www.freeguppy.org/download.php?lng=en http://www.freeguppy.org/thread.php?lng=en&pg=81882&fid=1&cat=200 http://www.securityfocus.com/bid/14753

Share on: