CVE-2012-4352 Information
Feb 14, 2021
cve
Description
Multiple cross-site scripting (XSS) vulnerabilities in Stoneware webNetwork 6.1 before SP1 allow remote attackers to inject arbitrary web script or HTML via the blogName parameter to (1) community/blog.jsp or (2) community/blogSearch.jsp the (3) calendarType or (4) monthNumber parameter to community/calendar.jsp or the (5) flag parameter to swDashboard/ajax/setAppFlag.jsp.
Reference
http://infosec42.blogspot.com/2012/10/stoneware-webnetwork-61-reflective-xss.html http://stoneware-docs.s3.amazonaws.com/Bulletins/Security20Bulletin206_1_0.pdf
Share on: