
Browse Database - By Creditee luny
| Researcher Name: | |||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Researcher Company: | |||||||||||||
| Researcher Country: | Unknown | ||||||||||||
| Vulnerabilities Types: |
|
Displaying vulnerabilities 1 - 40 of 142 in total
| OSVDB ID | Disclosure Date | Title | |
|---|---|---|---|
| 27321
[CLOSE] OSVDB ID : 27321 - Disclosed: 2006-07-13 Description: (Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in index.php in Orbitcoders OrbitMATRIX 1.0 allows remote attackers to inject arbitrary web script or HTML via the page_name parameter with an IMG tag containing a javascript URI in the SRC attribute. |
2006-07-13 | OrbitMATRIX index.php page_name Variable IMG Tag XSS | |
| 27322 | 2006-07-13 | OrbitMATRIX index.php page_name Parameter SQL Injection | |
| 27035
[CLOSE] OSVDB ID : 27035 - Disclosed: 2006-07-05 Description: TTCalc contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'year' and 'currency' variables upon submission to the loan.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity. |
2006-07-05 | TTCalc loan.php Multiple Parameter XSS | |
| 27036
[CLOSE] OSVDB ID : 27036 - Disclosed: 2006-07-05 Description: TTCalc contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'year' and 'currency' variables upon submission to the mortgage.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity. |
2006-07-05 | TTCalc mortgage.php Multiple Parameter XSS | |
| 27024
[CLOSE] OSVDB ID : 27024 - Disclosed: 2006-07-04 Description: Garry Glendown's Shopping Cart contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'product' variable upon submission to the 'edititem.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity. |
2006-07-04 | Glendown Shopping Cart edititem.php product Parameter XSS | |
| 27025
[CLOSE] OSVDB ID : 27025 - Disclosed: 2006-07-04 Description: Garry Glendown's Shopping Cart contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'name' variable upon submission to the 'editshop.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity. |
2006-07-04 | Glendown Shopping Cart editshop.php name Parameter XSS | |
| 26979
[CLOSE] OSVDB ID : 26979 - Disclosed: 2006-06-30 Description: Buddy Zone contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the view_sub_forum.php script not properly sanitizing user-supplied input to the 'main_cat' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database. Additionally, if a failed query is performed, the program will disclose the softwares installation path. While such information is relatively low risk, it is often useful in carrying out additional, more focused attacks. |
2006-06-30 | Buddy Zone view_sub_forum.php main_cat Parameter SQL Injection | |
| 26980
[CLOSE] OSVDB ID : 26980 - Disclosed: 2006-06-30 Description: Buddy Zone contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the view_classifieds.php script not properly sanitizing user-supplied input to the 'cat_id' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database. Additionally, if a failed query is performed, the program will disclose the softwares installation path. While such information is relatively low risk, it is often useful in carrying out additional, more focused attacks. |
2006-06-30 | Buddy Zone view_classifieds.php cat_id Parameter SQL Injection | |
| 26981
[CLOSE] OSVDB ID : 26981 - Disclosed: 2006-06-30 Description: Buddy Zone contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the view_ad.php script not properly sanitizing user-supplied input to the 'id' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database. Additionally, if a failed query is performed, the program will disclose the softwares installation path. While such information is relatively low risk, it is often useful in carrying out additional, more focused attacks. |
2006-06-30 | Buddy Zone view_ad.php id Parameter SQL Injection | |
| 26982
[CLOSE] OSVDB ID : 26982 - Disclosed: 2006-06-30 Description: Buddy Zone contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the view_event.php script not properly sanitizing user-supplied input to the 'event_id' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database. Additionally, if a failed query is performed, the program will disclose the softwares installation path. While such information is relatively low risk, it is often useful in carrying out additional, more focused attacks. |
2006-06-30 | Buddy Zone view_event.php event_id Parameter SQL Injection | |
| 26983
[CLOSE] OSVDB ID : 26983 - Disclosed: 2006-06-30 Description: Buddy Zone contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the delete_event.php script not properly sanitizing user-supplied input to the 'event_id' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database. Additionally, if a failed query is performed, the program will disclose the softwares installation path. While such information is relatively low risk, it is often useful in carrying out additional, more focused attacks. |
2006-06-30 | Buddy Zone delete_event.php event_id Parameter SQL Injection | |
| 26984
[CLOSE] OSVDB ID : 26984 - Disclosed: 2006-06-30 Description: Buddy Zone contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the edit_event.php script not properly sanitizing user-supplied input to the 'event_id' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database. Additionally, if a failed query is performed, the program will disclose the softwares installation path. While such information is relatively low risk, it is often useful in carrying out additional, more focused attacks. |
2006-06-30 | Buddy Zone edit_event.php event_id Parameter SQL Injection | |
| 26985
[CLOSE] OSVDB ID : 26985 - Disclosed: 2006-06-30 Description: Buddy Zone contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the view_group.php script not properly sanitizing user-supplied input to the 'group_id' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database. Additionally, if a failed query is performed, the program will disclose the softwares installation path. While such information is relatively low risk, it is often useful in carrying out additional, more focused attacks. |
2006-06-30 | Buddy Zone view_group.php group_id Parameter SQL Injection | |
| 26986
[CLOSE] OSVDB ID : 26986 - Disclosed: 2006-06-30 Description: Buddy Zone contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate form fields upon submission to the view_sub_forum.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity. |
2006-06-30 | Buddy Zone view_sub_forum.php XSS | |
| 26987
[CLOSE] OSVDB ID : 26987 - Disclosed: 2006-06-30 Description: Buddy Zone contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate form fields upon submission to the view_post.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity. |
2006-06-30 | Buddy Zone view_post.php XSS | |
| 26988
[CLOSE] OSVDB ID : 26988 - Disclosed: 2006-06-30 Description: Buddy Zone contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate form fields upon submission to the view_classifieds.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity. |
2006-06-30 | Buddy Zone view_classifieds.php XSS | |
| 26989
[CLOSE] OSVDB ID : 26989 - Disclosed: 2006-06-30 Description: Buddy Zone contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate form fields upon submission to the view_ad.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity. |
2006-06-30 | Buddy Zone view_ad.php XSS | |
| 26990
[CLOSE] OSVDB ID : 26990 - Disclosed: 2006-06-30 Description: Buddy Zone contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate form fields upon submission to the view_event.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity. |
2006-06-30 | Buddy Zone view_event.php XSS | |
| 26991
[CLOSE] OSVDB ID : 26991 - Disclosed: 2006-06-30 Description: Buddy Zone contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate form fields upon submission to the delete_event.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity. |
2006-06-30 | Buddy Zone delete_event.php XSS | |
| 26992
[CLOSE] OSVDB ID : 26992 - Disclosed: 2006-06-30 Description: Buddy Zone contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate form fields upon submission to the edit_event.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity. |
2006-06-30 | Buddy Zone edit_event.php XSS | |
| 26993
[CLOSE] OSVDB ID : 26993 - Disclosed: 2006-06-30 Description: Buddy Zone contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate form fields upon submission to the view_group.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity. |
2006-06-30 | Buddy Zone view_group.php XSS | |
| 26871 | 2006-06-25 | Metalhead Usenet Script index.php group Parameter XSS | |
| 26850
[CLOSE] OSVDB ID : 26850 - Disclosed: 2006-06-22 Description: (Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in Custom dating biz dating script 1.0 allows remote attackers to inject arbitrary web script or HTML via the (1) sn20_special_cases parameter ("Special Cases" field) in profile/mini.php, (2) tyxx01_album_name parameter ("Album Name" field) in profile/photo_create.php, and the (3) u parameter in admin/user_view.php. |
2006-06-22 | Custom dating biz dating script Profile Update Special Cases Field XSS | |
| 26851
[CLOSE] OSVDB ID : 26851 - Disclosed: 2006-06-22 Description: (Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in Custom dating biz dating script 1.0 allows remote attackers to inject arbitrary web script or HTML via the (1) sn20_special_cases parameter ("Special Cases" field) in profile/mini.php, (2) tyxx01_album_name parameter ("Album Name" field) in profile/photo_create.php, and the (3) u parameter in admin/user_view.php. |
2006-06-22 | Custom dating biz dating script photo_create.php Album Name Field XSS | |
| 26852
[CLOSE] OSVDB ID : 26852 - Disclosed: 2006-06-22 Description: (Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in Custom dating biz dating script 1.0 allows remote attackers to inject arbitrary web script or HTML via the (1) sn20_special_cases parameter ("Special Cases" field) in profile/mini.php, (2) tyxx01_album_name parameter ("Album Name" field) in profile/photo_create.php, and the (3) u parameter in admin/user_view.php. |
2006-06-22 | Custom dating biz dating script admin/user_view.php u Parameter XSS | |
| 26778 | 2006-06-20 | cjGuestbook sign.php Comment Parameter img BBCode Tag XSS | |
| 26659
[CLOSE] OSVDB ID : 26659 - Disclosed: 2006-06-18 Description: (Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in DKScript.com Dragon's Kingdom Script 1.0 allow remote attackers to inject arbitrary web script or HTML via a javascript URI in the SRC attribute of an IMG element in the (1) Subject and (2) Message fields in a do=write (aka Send Mail Message) action in gamemail.php; the (3) Gender, (4) Country/Location, (5) MSN Messenger, (6) AOL Instant Messenger, (7) Yahoo Instant Messenger, and (8) ICQ fields in a do=onlinechar (aka Edit your Profile) action in index.php, as accessed by dk.php; a javascript URI in the SRC attribute of an IMG element in the (9) Title and (10) Message fields in a do=new (aka Create Thread) action in general.php; and a javascript URI in the SRC attribute of an IMG element in unspecified fields in (11) other Forum posts and (12) Forum replies. |
2006-06-18 | Dragons Kingdom Mail Message Multiple Field XSS | |
| 26660
[CLOSE] OSVDB ID : 26660 - Disclosed: 2006-06-18 Description: (Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in DKScript.com Dragon's Kingdom Script 1.0 allow remote attackers to inject arbitrary web script or HTML via a javascript URI in the SRC attribute of an IMG element in the (1) Subject and (2) Message fields in a do=write (aka Send Mail Message) action in gamemail.php; the (3) Gender, (4) Country/Location, (5) MSN Messenger, (6) AOL Instant Messenger, (7) Yahoo Instant Messenger, and (8) ICQ fields in a do=onlinechar (aka Edit your Profile) action in index.php, as accessed by dk.php; a javascript URI in the SRC attribute of an IMG element in the (9) Title and (10) Message fields in a do=new (aka Create Thread) action in general.php; and a javascript URI in the SRC attribute of an IMG element in unspecified fields in (11) other Forum posts and (12) Forum replies. |
2006-06-18 | Dragons Kingdom Forum Post Multiple Field XSS | |
| 26661
[CLOSE] OSVDB ID : 26661 - Disclosed: 2006-06-18 Description: (Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in DKScript.com Dragon's Kingdom Script 1.0 allow remote attackers to inject arbitrary web script or HTML via a javascript URI in the SRC attribute of an IMG element in the (1) Subject and (2) Message fields in a do=write (aka Send Mail Message) action in gamemail.php; the (3) Gender, (4) Country/Location, (5) MSN Messenger, (6) AOL Instant Messenger, (7) Yahoo Instant Messenger, and (8) ICQ fields in a do=onlinechar (aka Edit your Profile) action in index.php, as accessed by dk.php; a javascript URI in the SRC attribute of an IMG element in the (9) Title and (10) Message fields in a do=new (aka Create Thread) action in general.php; and a javascript URI in the SRC attribute of an IMG element in unspecified fields in (11) other Forum posts and (12) Forum replies. |
2006-06-18 | Dragons Kingdom User Profile Multiple Field XSS | |
| 26715
[CLOSE] OSVDB ID : 26715 - Disclosed: 2006-06-17 Description: (Description Provided by CVE) : V3 Chat allows remote attackers to obtain the installation path via (1) an invalid id parameter to mail/index.php or (2) membername parameter to messenger/online.php, which displays the path in an error page due to an incorrect SQL statement. |
2006-06-17 | V3 Chat Instant Messenger mail/index.php id Parameter SQL Injection | |
| 26716 | 2006-06-17 | V3 Chat Instant Messenger online.php membername Parameter SQL Injection | |
| 26717
[CLOSE] OSVDB ID : 26717 - Disclosed: 2006-06-17 Description: (Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in V3 Chat allow remote attackers to inject arbitrary web script or HTML via crafted HTML tags, as demonstrated by the IMG tag, in the (1) id parameter in (a) mail/index.php and (b) mail/reply.php; (2) login_id parameter in (c) members/is_online.php; (3) site_id parameter in (d) messenger/online.php, (e) messenger/search.php, and (f) messenger/profile.php; (4) contact_name parameter in messenger/search.php; (5) membername parameter in (g) messenger/profileview.php; (6) unspecified parameters used when "editing a profile"; and (7) cust_name parameter in (h) messenger/expire.php. NOTE: The vendor disputes the vectors involving files in the messenger directory, stating "... the referenced folder 'messenger' was never available to the general public...". |
2006-06-17 | V3 Chat Instant Messenger mail/index.php id Parameter XSS | |
| 26718
[CLOSE] OSVDB ID : 26718 - Disclosed: 2006-06-17 Description: (Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in V3 Chat allow remote attackers to inject arbitrary web script or HTML via crafted HTML tags, as demonstrated by the IMG tag, in the (1) id parameter in (a) mail/index.php and (b) mail/reply.php; (2) login_id parameter in (c) members/is_online.php; (3) site_id parameter in (d) messenger/online.php, (e) messenger/search.php, and (f) messenger/profile.php; (4) contact_name parameter in messenger/search.php; (5) membername parameter in (g) messenger/profileview.php; (6) unspecified parameters used when "editing a profile"; and (7) cust_name parameter in (h) messenger/expire.php. NOTE: The vendor disputes the vectors involving files in the messenger directory, stating "... the referenced folder 'messenger' was never available to the general public...". |
2006-06-17 | V3 Chat Instant Messenger mail/reply.php id Parameter XSS | |
| 26719
[CLOSE] OSVDB ID : 26719 - Disclosed: 2006-06-17 Description: (Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in V3 Chat allow remote attackers to inject arbitrary web script or HTML via crafted HTML tags, as demonstrated by the IMG tag, in the (1) id parameter in (a) mail/index.php and (b) mail/reply.php; (2) login_id parameter in (c) members/is_online.php; (3) site_id parameter in (d) messenger/online.php, (e) messenger/search.php, and (f) messenger/profile.php; (4) contact_name parameter in messenger/search.php; (5) membername parameter in (g) messenger/profileview.php; (6) unspecified parameters used when "editing a profile"; and (7) cust_name parameter in (h) messenger/expire.php. NOTE: The vendor disputes the vectors involving files in the messenger directory, stating "... the referenced folder 'messenger' was never available to the general public...". |
2006-06-17 | V3 Chat Instant Messenger is_online.php login_id Parameter XSS | |
| 26720
[CLOSE] OSVDB ID : 26720 - Disclosed: 2006-06-17 Description: (Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in V3 Chat allow remote attackers to inject arbitrary web script or HTML via crafted HTML tags, as demonstrated by the IMG tag, in the (1) id parameter in (a) mail/index.php and (b) mail/reply.php; (2) login_id parameter in (c) members/is_online.php; (3) site_id parameter in (d) messenger/online.php, (e) messenger/search.php, and (f) messenger/profile.php; (4) contact_name parameter in messenger/search.php; (5) membername parameter in (g) messenger/profileview.php; (6) unspecified parameters used when "editing a profile"; and (7) cust_name parameter in (h) messenger/expire.php. NOTE: The vendor disputes the vectors involving files in the messenger directory, stating "... the referenced folder 'messenger' was never available to the general public...". |
2006-06-17 | V3 Chat Instant Messenger online.php site_id Parameter XSS | |
| 26721
[CLOSE] OSVDB ID : 26721 - Disclosed: 2006-06-17 Description: (Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in V3 Chat allow remote attackers to inject arbitrary web script or HTML via crafted HTML tags, as demonstrated by the IMG tag, in the (1) id parameter in (a) mail/index.php and (b) mail/reply.php; (2) login_id parameter in (c) members/is_online.php; (3) site_id parameter in (d) messenger/online.php, (e) messenger/search.php, and (f) messenger/profile.php; (4) contact_name parameter in messenger/search.php; (5) membername parameter in (g) messenger/profileview.php; (6) unspecified parameters used when "editing a profile"; and (7) cust_name parameter in (h) messenger/expire.php. NOTE: The vendor disputes the vectors involving files in the messenger directory, stating "... the referenced folder 'messenger' was never available to the general public...". |
2006-06-17 | V3 Chat Instant Messenger search.php Multiple Parameter XSS | |
| 26722
[CLOSE] OSVDB ID : 26722 - Disclosed: 2006-06-17 Description: (Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in V3 Chat allow remote attackers to inject arbitrary web script or HTML via crafted HTML tags, as demonstrated by the IMG tag, in the (1) id parameter in (a) mail/index.php and (b) mail/reply.php; (2) login_id parameter in (c) members/is_online.php; (3) site_id parameter in (d) messenger/online.php, (e) messenger/search.php, and (f) messenger/profile.php; (4) contact_name parameter in messenger/search.php; (5) membername parameter in (g) messenger/profileview.php; (6) unspecified parameters used when "editing a profile"; and (7) cust_name parameter in (h) messenger/expire.php. NOTE: The vendor disputes the vectors involving files in the messenger directory, stating "... the referenced folder 'messenger' was never available to the general public...". |
2006-06-17 | V3 Chat Instant Messenger profile.php site_id Parameter XSS | |
| 26723
[CLOSE] OSVDB ID : 26723 - Disclosed: 2006-06-17 Description: (Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in V3 Chat allow remote attackers to inject arbitrary web script or HTML via crafted HTML tags, as demonstrated by the IMG tag, in the (1) id parameter in (a) mail/index.php and (b) mail/reply.php; (2) login_id parameter in (c) members/is_online.php; (3) site_id parameter in (d) messenger/online.php, (e) messenger/search.php, and (f) messenger/profile.php; (4) contact_name parameter in messenger/search.php; (5) membername parameter in (g) messenger/profileview.php; (6) unspecified parameters used when "editing a profile"; and (7) cust_name parameter in (h) messenger/expire.php. NOTE: The vendor disputes the vectors involving files in the messenger directory, stating "... the referenced folder 'messenger' was never available to the general public...". |
2006-06-17 | V3 Chat Instant Messenger profileview.php membername Parameter XSS | |
| 26724
[CLOSE] OSVDB ID : 26724 - Disclosed: 2006-06-17 Description: (Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in V3 Chat allow remote attackers to inject arbitrary web script or HTML via crafted HTML tags, as demonstrated by the IMG tag, in the (1) id parameter in (a) mail/index.php and (b) mail/reply.php; (2) login_id parameter in (c) members/is_online.php; (3) site_id parameter in (d) messenger/online.php, (e) messenger/search.php, and (f) messenger/profile.php; (4) contact_name parameter in messenger/search.php; (5) membername parameter in (g) messenger/profileview.php; (6) unspecified parameters used when "editing a profile"; and (7) cust_name parameter in (h) messenger/expire.php. NOTE: The vendor disputes the vectors involving files in the messenger directory, stating "... the referenced folder 'messenger' was never available to the general public...". |
2006-06-17 | V3 Chat Instant Messenger expire.php cust_name Parameter XSS | |
| 26725
[CLOSE] OSVDB ID : 26725 - Disclosed: 2006-06-17 Description: (Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in V3 Chat allow remote attackers to inject arbitrary web script or HTML via crafted HTML tags, as demonstrated by the IMG tag, in the (1) id parameter in (a) mail/index.php and (b) mail/reply.php; (2) login_id parameter in (c) members/is_online.php; (3) site_id parameter in (d) messenger/online.php, (e) messenger/search.php, and (f) messenger/profile.php; (4) contact_name parameter in messenger/search.php; (5) membername parameter in (g) messenger/profileview.php; (6) unspecified parameters used when "editing a profile"; and (7) cust_name parameter in (h) messenger/expire.php. NOTE: The vendor disputes the vectors involving files in the messenger directory, stating "... the referenced folder 'messenger' was never available to the general public...". |
2006-06-17 | V3 Chat Instant Messenger Profile Edit Filter Bypass XSS |
The database information may change without any notice. Use of the information constitutes acceptance for use in an AS IS condition, and there are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the copyright holder or distributor (OSVDB or OSF) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
© Copyright 2002 - 2013 Open Source Vulnerability Database (OSVDB), All Rights Reserved.
Privacy Statement - Terms of Use