CVE-2007-5985 Information

Description

Multiple cross-site scripting (XSS) vulnerabilities in BtiTracker before 1.4.5 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors to (1) account.php (2) moresmiles.php or (3) recover.php; or (4) the \to\ parameter to usercp.php.

Reference

http://osvdb.org/38751 http://osvdb.org/38752 http://osvdb.org/38753 http://osvdb.org/38754 http://osvdb.org/42219 http://osvdb.org/42220 http://osvdb.org/42221 http://osvdb.org/42222 http://secunia.com/advisories/27550 http://sourceforge.net/forum/forum.php?forum_id=752472 http://sourceforge.net/project/shownotes.php?group_id=146822&release_id=552477 http://sourceforge.net/tracker/index.php?func=detail&aid=1753797&group_id=146822&atid=766508 http://www.securityfocus.com/bid/26551 https://exchange.xforce.ibmcloud.com/vulnerabilities/38413 https://exchange.xforce.ibmcloud.com/vulnerabilities/38414

Share on: