CVE-2012-1219 Information

Description

Multiple cross-site scripting (XSS) vulnerabilities in freelancerKit 2.35 allow remote attackers to inject arbitrary web script or HTML via the (1) ticket parameter to tickets.php (2) title parameter to notes.php or (3) task parameter to todo.php. NOTE: some of these details are obtained from third party information.

Reference

http://secunia.com/advisories/47766 http://www.securityfocus.com/bid/51946 http://www.vulnerability-lab.com/get_content.php?id=402 https://exchange.xforce.ibmcloud.com/vulnerabilities/73104

Share on: