LWN.net Logo

b2evolution: cross-site scripting

Package(s):b2evolution CVE #(s):CVE-2007-0175
Created:May 5, 2008 Updated:May 7, 2008
Description:

From the CVE entry:

Cross-site scripting (XSS) vulnerability in htsrv/login.php in b2evolution 1.8.6 allows remote attackers to inject arbitrary web script or HTML via scriptable attributes in the redirect_to parameter.

Alerts:
Debian DSA-1568-1 2008-05-05

(Log in to post comments)

Copyright © 2008, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds
Powered by Rackspace Managed Hosting.