CVE-2009-3359 Information

Description

Multiple cross-site scripting (XSS) vulnerabilities in Match Agency BiZ 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) important parameter to edit_profile.php and (2) pid parameter to report.php.

Reference

http://osvdb.org/57968 http://osvdb.org/57969 http://packetstormsecurity.org/0909-exploits/matchagencybiz-xss.txt http://secunia.com/advisories/36672 https://exchange.xforce.ibmcloud.com/vulnerabilities/53173

Share on: