Heap
14-04-09, 02:55
Multiple cross-site scripting (XSS) vulnerabilities in Pre ADS Portal 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the msg parameter to (1) homeadmin/adminhome.php and (2) homeadmin/signinform.php.
More... (http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-6715)
More... (http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-6715)