CVE-2008-6891 Information

Description

Multiple cross-site scripting (XSS) vulnerabilities in ASP Forum Script allow remote attackers to inject arbitrary web script or HTML via the (1) forum_id parameter to (a) new_message.asp and (b) messages.asp and the (2) query string to default.asp.

Reference

http://packetstormsecurity.org/0812-exploits/aspforum-cmsqlxss.txt http://www.securityfocus.com/bid/32571 https://exchange.xforce.ibmcloud.com/vulnerabilities/47002

Share on: