CVE-2010-4407 Information

Description

Multiple cross-site scripting (XSS) vulnerabilities in index.php in AlGuest 1.1c-patched allow remote attackers to inject arbitrary web script or HTML via the (1) nome (nickname) (2) messaggio (message) and (3) link (homepage) parameters.

Reference

http://evuln.com/vulns/151/summary.html http://packetstormsecurity.org/files/view/96297/alguest-xss.txt http://www.securityfocus.com/archive/1/514960/100/0/threaded http://www.securityfocus.com/bid/45140

Share on: