CVE-2006-1436 Information

Description

Multiple cross-site scripting (XSS) vulnerabilities in UPOINT @1 Event Publisher allow remote attackers to inject arbitrary web script or HTML via the (1) Event (2) Description (3) Time (4) Website and (5) Public Remarks fields to (a) eventpublisher_admin.htm and (b) eventpublisher_usersubmit.htm.

Reference

http://osvdb.org/ref/24/24236-upoint.txt http://secunia.com/advisories/19727 http://www.osvdb.org/24235 http://www.osvdb.org/24236 http://www.securityfocus.com/bid/17646

Share on: