Required CVE Record Information
Description
Multiple cross-site scripting (XSS) vulnerabilities in admin/header.php in Toms Gaestebuch 1.01 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) lang[adminseite], (2) lang[ueberschrift], or (3) einst[metachar] parameter, different vectors than CVE-2007-4711.
References 6 Total
- osvdb.org: 38660 vdb-entry
- http://www.toms-seiten.at/guest/index.php?language=de
- http://www.toms-seiten.at/iv_downloads/details.php?dl_id=3&language=de
- securityfocus.com: 20070919 Re: Re: Re: Toms Gästebuch 1.00 - XSS mailing-list
- securityfocus.com: 20070908 Re: Re: Toms Gästebuch 1.00 - XSS mailing-list
- securityfocus.com: 25598 vdb-entry
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 6 Total
- osvdb.org: 38660 vdb-entryx_transferred
- http://www.toms-seiten.at/guest/index.php?language=de x_transferred
- http://www.toms-seiten.at/iv_downloads/details.php?dl_id=3&language=de x_transferred
- securityfocus.com: 20070919 Re: Re: Re: Toms Gästebuch 1.00 - XSS mailing-listx_transferred
- securityfocus.com: 20070908 Re: Re: Toms Gästebuch 1.00 - XSS mailing-listx_transferred
- securityfocus.com: 25598 vdb-entryx_transferred