Required CVE Record Information
Description
Multiple cross-site scripting (XSS) vulnerabilities in index.html in Wowd client before 1.3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) sortby, (2) tags, or (3) ctx parameter in a search action.
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 3 Total
- http://lostmon.blogspot.com/2009/10/wowd-search-client-multiple-variable.html x_transferred
- vupen.com: ADV-2009-3071 vdb-entryx_transferred
- http://packetstormsecurity.org/0910-exploits/wowd-xss.txt x_transferred