![]() | |
| |||||||
| Home | Register | Projects | Blogs | FAQ | Calendar | Search | Today's Posts | Mark Forums Read | Free Directory | Free DNSReport | Tags |
| Notices |
| Advisories Discuss about all newly security flaws classed by CVE entries and reviewed by security experts |
CVE-2007-5727 (OneOrZero Helpdesk)This is a discussion on "CVE-2007-5727 (OneOrZero Helpdesk)" within the Advisories part of the Computer Security: Discussions section; Incomplete blacklist vulnerability in the stripScripts function in common.php in OneOrZero Helpdesk 1.6.5.4, 1.6.4.2, and possibly other versions, allows remote attackers to conduct cross-site scripting (XSS) attacks and inject arbitrary web script ... |
![]() |
| | LinkBack | Thread Tools | Display Modes |
| |||
| Incomplete blacklist vulnerability in the stripScripts function in common.php in OneOrZero Helpdesk 1.6.5.4, 1.6.4.2, and possibly other versions, allows remote attackers to conduct cross-site scripting (XSS) attacks and inject arbitrary web script or HTML via XSS sequences without SCRIPT tags in the description parameter to (1) tcreate.php or (2) tupdate.php, as demonstrated using an onmouseover event in a b tag. More... |
| Sponsor | ||
| ||
| |
![]() |
| | |
| cve20075727, helpdesk, oneorzero | |
| Thread Tools | |
| Display Modes | |
| |
Similar Threads | ||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Microsoft Service Packs Going Out of Support - May 2007 | class101 | Security discussions | 0 | 02-05-07 01:08 |