![]() | |
| |||||||
| Home | Register | Projects | Blogs | FAQ | Calendar | Search | Today's Posts | Mark Forums Read | Free Directory | Free DNSReport | Tags |
| Notices |
| Advisories Discuss about all newly security flaws classed by CVE entries and reviewed by security experts |
CVE-2008-0605 (AstroSoft HelpDesk)This is a discussion on "CVE-2008-0605 (AstroSoft HelpDesk)" within the Advisories part of the Computer Security: Discussions section; Multiple cross-site scripting (XSS) vulnerabilities in AstroSoft HelpDesk allow remote attackers to inject arbitrary web script or HTML via the (1) txtSearch parameter to operator/article/article_search_results.asp and the (2) Attach_Id parameter to operator/article/article_attachment.asp. NOTE: ... |
![]() |
| | LinkBack | Thread Tools | Display Modes |
| |||
| Multiple cross-site scripting (XSS) vulnerabilities in AstroSoft HelpDesk allow remote attackers to inject arbitrary web script or HTML via the (1) txtSearch parameter to operator/article/article_search_results.asp and the (2) Attach_Id parameter to operator/article/article_attachment.asp. NOTE: for vector 2, the XSS occurs in a forced SQL error message. More... |
| Sponsor | ||
| ||
| |