CENTER.HU groups
CENTER.HU address

User:

Guest

www.center.hu / Archive / Security news / february, 2005 / CVSTrac cross-site scripting vulnerability 

CVSTrac cross-site scripting vulnerability

CVSTrac cross-site scripting vulnerability

Date Discovered: December 17, 2004
Date Published: February 1, 2005
Last Updated: February 1, 2005

Vulnerability Description

Vulnerability ID:          32104
Discovered by:            Michael Krax
Exploitable Locally:     No
Exploitable Remotely: Yes
Impact:                        Remote attackers can launch cross-site scripting attacks.
Root Cause:                 Software Vulnerability

CVSTrac contains a vulnerability that may allow remote attackers to launch cross-site scripting attacks. The vulnerability exists in main.c and login.c and is due to improper filtering of user supplied data. Remote attackers can exploit this vulnerability to inject arbitrary HTML and launch a variety of cross-site scripting attacks.

 

 

More information on CA Vulnerability Information Center
http://www3.ca.com/securityadvisor/vulninfo/vuln.aspx?id=32104

Computer Associates – the Trusted Source of Security Knowledge

 

Back




Copyright © CENTER.HU Ltd, 2000-2010. All rights reserved

sitemap | privacy policy |

copyrights | new pages |

terms of purchase | contact us


PARTNERS: Computerworld.hu | GameStar.hu | PCWorld.hu | SG.hu | PC Guru | Hitel