Required CVE Record Information
Description
Cross-site scripting (XSS) vulnerability in app/controllers/todos_controller.rb in Tracks 1.7.2, 2.0RC2, and 2.0devel allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to todos/tag/. NOTE: some of these details are obtained from third party information.
References 8 Total
- osvdb.org: 71352 vdb-entry
- securityfocus.com: 20110329 XSS Vulnerability in Tracks 1.7.2 mailing-list
- http://www.mavitunasecurity.com/XSS-vulnerability-in-Tracks/
- securityreason.com: 8196 third-party-advisory
- securityfocus.com: 47078 vdb-entry
- secunia.com: 43909 third-party-advisory
- http://www.getontracks.org/downloads/comments/tracks-173
- exchange.xforce.ibmcloud.com: tracks-todoscontroller-xss(66561) vdb-entry
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 8 Total
- osvdb.org: 71352 vdb-entryx_transferred
- securityfocus.com: 20110329 XSS Vulnerability in Tracks 1.7.2 mailing-listx_transferred
- http://www.mavitunasecurity.com/XSS-vulnerability-in-Tracks/ x_transferred
- securityreason.com: 8196 third-party-advisoryx_transferred
- securityfocus.com: 47078 vdb-entryx_transferred
- secunia.com: 43909 third-party-advisoryx_transferred
- http://www.getontracks.org/downloads/comments/tracks-173 x_transferred
- exchange.xforce.ibmcloud.com: tracks-todoscontroller-xss(66561) vdb-entryx_transferred