CVE-2010-1995 Information

Description

Multiple cross-site scripting (XSS) vulnerabilities in index.php in TomatoCMS before 2.0.5 allow remote authenticated users with \Add new article\ privileges to inject arbitrary web script or HTML via the (1) title (2) subTitle and (3) author parameters in conjunction with a /admin/news/article/add PATH_INFO.

Reference

http://holisticinfosec.org/content/view/141/45/ http://osvdb.org/64550 http://secunia.com/advisories/39320 http://secunia.com/secunia_research/2010-59/ http://www.securityfocus.com/archive/1/511272/100/0/threaded http://www.securityfocus.com/bid/40108 https://exchange.xforce.ibmcloud.com/vulnerabilities/58471

Share on: