LWN.net Logo

jpgraph: multiple cross-site scripting vulnerabilities

Package(s):jpgraph CVE #(s):CVE-2009-4422
Created:December 28, 2009 Updated:January 6, 2010
Description:

From the Mandriva advisory:

Multiple cross-site scripting (XSS) vulnerabilities in the GetURLArguments function in jpgraph.php in Aditus Consulting JpGraph 3.0.6 allow remote attackers to inject arbitrary web script or HTML via a key to csim_in_html_ex1.php, and other unspecified vectors (CVE-2009-4422).

Alerts:
Mandriva MDVSA-2009:340 2009-12-26

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds