Cross-site scripting (XSS) vulnerability in ScrewTurn Wiki 2.0.29 and 2.0.30 allows remote attackers to inject arbitrary web script or HTML via error messages in the "/admin.aspx - System Log" page.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 00:49
Type | Values Removed | Values Added |
---|---|---|
References | () http://secunia.com/advisories/31242 - Vendor Advisory | |
References | () http://www.portcullis.co.uk/281.php - | |
References | () http://www.screwturn.eu/Wiki.ashx#History_2 - | |
References | () http://www.securityfocus.com/bid/30429 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/42858 - |
Information
Published : 2008-08-05 20:41
Updated : 2024-11-21 00:49
NVD link : CVE-2008-3483
Mitre link : CVE-2008-3483
CVE.ORG link : CVE-2008-3483
JSON object : View
Products Affected
screwturn
- screwturn_wiki
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')