Required CVE Record Information
Description
Multiple cross-site scripting (XSS) vulnerabilities in BtiTracker before 1.4.5 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors to (1) account.php, (2) moresmiles.php, or (3) recover.php; or (4) the "to" parameter to usercp.php.
References 15 Total
- osvdb.org: 38753 vdb-entry
- osvdb.org: 42219 vdb-entry
- http://sourceforge.net/tracker/index.php?func=detail&aid=1753797&group_id=146822&atid=766508
- exchange.xforce.ibmcloud.com: btitracker-multiple-scripts-xss(38413) vdb-entry
- exchange.xforce.ibmcloud.com: btitracker-usercp-xss(38414) vdb-entry
- osvdb.org: 38754 vdb-entry
- osvdb.org: 42222 vdb-entry
- osvdb.org: 42220 vdb-entry
- http://sourceforge.net/project/shownotes.php?group_id=146822&release_id=552477
- osvdb.org: 38751 vdb-entry
- http://sourceforge.net/forum/forum.php?forum_id=752472
- secunia.com: 27550 third-party-advisory
- securityfocus.com: 26551 vdb-entry
- osvdb.org: 42221 vdb-entry
- osvdb.org: 38752 vdb-entry
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 15 Total
- osvdb.org: 38753 vdb-entryx_transferred
- osvdb.org: 42219 vdb-entryx_transferred
- http://sourceforge.net/tracker/index.php?func=detail&aid=1753797&group_id=146822&atid=766508 x_transferred
- exchange.xforce.ibmcloud.com: btitracker-multiple-scripts-xss(38413) vdb-entryx_transferred
- exchange.xforce.ibmcloud.com: btitracker-usercp-xss(38414) vdb-entryx_transferred
- osvdb.org: 38754 vdb-entryx_transferred
- osvdb.org: 42222 vdb-entryx_transferred
- osvdb.org: 42220 vdb-entryx_transferred
- http://sourceforge.net/project/shownotes.php?group_id=146822&release_id=552477 x_transferred
- osvdb.org: 38751 vdb-entryx_transferred
- http://sourceforge.net/forum/forum.php?forum_id=752472 x_transferred
- secunia.com: 27550 third-party-advisoryx_transferred
- securityfocus.com: 26551 vdb-entryx_transferred
- osvdb.org: 42221 vdb-entryx_transferred
- osvdb.org: 38752 vdb-entryx_transferred