CVE-2010-2344 Information

Description

Multiple cross-site scripting (XSS) vulnerabilities in odCMS 1.06 and possibly earlier allow remote attackers to inject arbitrary web script or HTML via the Page parameter to (1) _main/index.php (2) _members/index.php (3) _forum/index.php (4) _docs/index.php and (5) _announcements/index.php.

Reference

http://holisticinfosec.org/content/view/146/45/ http://secunia.com/advisories/39942 http://www.osvdb.org/65258 http://www.osvdb.org/65259 http://www.osvdb.org/65260 http://www.osvdb.org/65261 http://www.osvdb.org/65262 http://www.securityfocus.com/bid/40678 https://exchange.xforce.ibmcloud.com/vulnerabilities/59247

Share on: