CVE-2005-4485 Information

Description

Multiple cross-site scripting (XSS) vulnerabilities in ProjectApp 3.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the keywords parameter to (1) forums.asp (2) search_employees.asp (3) cat.asp and (4) links.asp; (5) projectid parameter to pmprojects.asp (6) ret_page parameter to login.asp and (7) skin_number parameter to default.asp.

Reference

http://pridels0.blogspot.com/2005/12/projectapp-mutliple-xss-vuln.html http://secunia.com/advisories/18199 http://www.osvdb.org/21962 http://www.osvdb.org/21963 http://www.osvdb.org/21964 http://www.osvdb.org/21965 http://www.osvdb.org/21966 http://www.osvdb.org/21967 http://www.osvdb.org/21968 http://www.securityfocus.com/bid/16011 http://www.vupen.com/english/advisories/2005/3040

Share on: