CVE-2013-0129 Information

Description

Multiple cross-site scripting (XSS) vulnerabilities in pd-admin before 4.17 allow remote authenticated users to inject arbitrary web script or HTML via (1) the WebFTP Overview \Create new directory\ field or (2) the body of an e-mail autoresponder message.

Reference

http://www.kb.cert.org/vuls/id/311644 http://www.pdadmin-forum.de/thread.php?threadid=4051

Share on: