Required CVE Record Information
Description
Cross-site scripting (XSS) vulnerability in multiple Rocomotion products, including P board 1.18 and other versions, P forum 1.30 and earlier, P up board 1.38 and other versions, P diary R 1.13 and earlier, P link 1.11 and earlier, P link compact 1.04 and earlier, pplog 3.31 and earlier, pplog2 3.37 and earlier, PM bbs 1.07 and earlier, PM up bbs 1.08 and earlier, and PM forum 1.18 and earlier, allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
References 7 Total
- jvn.jp: JVN#09115481 third-party-advisory
- secunia.com: 42957 third-party-advisory
- jvndb.jvn.jp: JVNDB-2011-000006 third-party-advisory
- securityfocus.com: 45838 vdb-entry
- exchange.xforce.ibmcloud.com: rocomotion-unspecified-xss(64745) vdb-entry
- http://another.rocomotion.jp/12949466953653.html
- osvdb.org: 70495 vdb-entry
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 7 Total
- jvn.jp: JVN#09115481 third-party-advisoryx_transferred
- secunia.com: 42957 third-party-advisoryx_transferred
- jvndb.jvn.jp: JVNDB-2011-000006 third-party-advisoryx_transferred
- securityfocus.com: 45838 vdb-entryx_transferred
- exchange.xforce.ibmcloud.com: rocomotion-unspecified-xss(64745) vdb-entryx_transferred
- http://another.rocomotion.jp/12949466953653.html x_transferred
- osvdb.org: 70495 vdb-entryx_transferred