CVE-2008-1225 Information

Description

Multiple cross-site scripting (XSS) vulnerabilities in WebCT Campus Edition 4.1.5.8 when \Don’t wrap text\ is enabled allow remote authenticated users to inject arbitrary web script or HTML via a (1) mail message or (2) discussion board message. NOTE: this might overlap CVE-2005-1076.

Reference

http://marc.info/?l=full-disclosure&m=120471944119467&w=2 http://secunia.com/advisories/29227 http://www.balupton.com/blogs/dev?title=webct_session_stealer_exploit http://www.balupton.com/documents/webct_exploits.txt http://www.securityfocus.com/bid/28107 https://exchange.xforce.ibmcloud.com/vulnerabilities/41047

Share on: