LWN.net Logo

online-bookmarks: multiple vulnerabilities

Package(s):online-bookmarks CVE #(s):CVE-2004-2155 CVE-2006-6358 CVE-2006-6359
Created:January 13, 2009 Updated:January 14, 2009
Description: From the Gentoo advisory: The following vulnerabilities were reported:

* Authentication bypass when directly requesting certain pages (CVE-2004-2155).

* Insufficient input validation in the login function in auth.inc (CVE-2006-6358).

* Unspecified cross-site scripting vulnerability (CVE-2006-6359).

A remote attacker could exploit these vulnerabilities to bypass authentication mechanisms, execute arbitrary SQL statements or inject arbitrary web scripts.

Alerts:
Gentoo 200901-08 2009-01-12

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds