Secunia Logo
 
CVE Reference: CVE-2004-0067
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2004-0067

Description:
Multiple cross-site scripting (XSS) vulnerabilities in phpGedView before 2.65 allow remote attackers to inject arbitrary HTML or web script via (1) descendancy.php, (2) index.php, (3) individual.php, (4) login.php, (5) relationship.php, (6) source.php, (7) imageview.php, (8) calendar.php, (9) gedrecord.php, (10) login.php, and (11) gdbi_interface.php. NOTE: some aspects of vector 10 were later reported to affect 4.1.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/36285
  http://xforce.iss.net/xforce/xfdb/14212

ST
  1018613

SAID
  Secunia Advisory: SA26628

OSVDB
  3473
  3474
  3475
  3476
  3477
  3478

BUGTRAQ
  http://www.securityfocus.com/archive/1/archive/1/477881/100/0/threaded
  http://marc.theaimsgroup.com/?l=bugtraq&m=107394912715478&w=2

BID
  11868
  11880
  11882
  11888
  11890
  11891
  11894
  11903
  11904
  11905
  11906
  11907


Return to the previous page.