CVE-2010-4355 Information

Description

Cross-site scripting (XSS) vulnerability in DaDaBIK before 4.3 beta2 when the insert or edit feature is enabled allows remote authenticated users to inject arbitrary web script or HTML via the select_single parameter.

Reference

http://secunia.com/advisories/42220 http://www.dadabik.org/index.php?function=show_changelog http://www.securityfocus.com/bid/44826 https://exchange.xforce.ibmcloud.com/vulnerabilities/63219

Share on: