CVE-2005-3814 Information

Description

Multiple cross-site scripting (XSS) vulnerabilities in SmartPPC Pro allow remote attackers to inject arbitrary web script or HTML via the username parameter in (1) directory.php (2) frames.php and (3) search.php.

Reference

http://nightmaresecurity.net/index.php?showtopic=1015 http://secunia.com/advisories/17736 http://securitytracker.com/id?1015259 http://www.addict3d.org/index.php?page=viewarticle&type=security&ID=5359 http://www.osvdb.org/21090 http://www.osvdb.org/21091 http://www.osvdb.org/21092 http://www.securityfocus.com/bid/15567 http://www.vupen.com/english/advisories/2005/2581

Share on: