CVE-2006-2953

Cross-site scripting (XSS) vulnerability in default.asp in OfficeFlow 2.6 and earlier allows remote attackers to inject arbitrary web script or HTML via the sqlType parameter.
Configurations

Configuration 1 (hide)

cpe:2.3:a:primoris_software:officeflow:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2006-06-12 20:06

Updated : 2024-02-04 16:52


NVD link : CVE-2006-2953

Mitre link : CVE-2006-2953

CVE.ORG link : CVE-2006-2953


JSON object : View

Products Affected

primoris_software

  • officeflow