Required CVE Record Information
Description
Cross-site scripting (XSS) vulnerability in addentry.cgi in ZAP 1.0.3 allows remote attackers to inject arbitrary SSi directives, web script, and HTML via the entry field.
References 5 Total
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 5 Total
- online.securityfocus.com: 20020629 SSI & CSS execution in E-Guest (1.1) & ZAP Book (v1.0.3) mailing-listx_transferred
- securityfocus.com: 5130 vdb-entryx_transferred
- iss.net: zapbook-entry-xss(9471) vdb-entryx_transferred
- securityfocus.com: 5131 vdb-entryx_transferred
- iss.net: zapbook-ssi-command-execution(9472) vdb-entryx_transferred