CVE-2009-2589 Information

Description

Multiple cross-site scripting (XSS) vulnerabilities in Hutscripts PHP Website Script allow remote attackers to inject arbitrary web script or HTML via the msg parameter to (1) feedback.php (2) index.php and (3) lostpassword.php.

Reference

http://osvdb.org/56170 http://osvdb.org/56171 http://osvdb.org/56172 http://packetstormsecurity.org/0907-exploits/hutscript-sqlxss.txt http://secunia.com/advisories/35893 http://www.vupen.com/english/advisories/2009/1978 https://exchange.xforce.ibmcloud.com/vulnerabilities/51912

Share on: