CVE-2009-4859 Information

Description

Multiple cross-site scripting (XSS) vulnerabilities in Online Work Order Suite (OWOS) Lite Edition 3.10 allow remote attackers to inject arbitrary web script or HTML via the show parameter to (1) default.asp and (2) report.asp and the (3) go parameter to login.asp.

Reference

http://packetstormsecurity.org/0908-exploits/owosasp-xss.txt http://secunia.com/advisories/36244

Share on: