| HIO-2009-0322 OpenGoo 1.3.1 XSS & script insertion |
|
|
|
|
OpenGoo 1.3.1 exhibits vulnerabilities which can be exploited by malicious people to conduct cross-site scripting attacks and by malicious users to conduct script insertion attacks. 1) Input passed via the "search_for" parameter in index.php when performing a search is not properly sanitised before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user's browser session in the context of an affected site. CVE-2009-pending BID: 34428 FrSIRT: N/A Nessus:N/A SA: 34420 Related: Vendor Solution: |
| < Prev | Next > |
|---|







