Multiple cross-site scripting (XSS) vulnerabilities in Butterfly Organizer 2.0.0 allow remote attackers to inject arbitrary web script or HTML via the (1) mytable parameter to view.php, (2) mytable parameter to viewdb2.php, (3) tablehere parameter to category-rename.php, and (4) letter parameter to module-contacts.php.
References
Configurations
History
No history.
Information
Published : 2009-04-10 22:00
Updated : 2024-02-04 17:33
NVD link : CVE-2008-6700
Mitre link : CVE-2008-6700
CVE.ORG link : CVE-2008-6700
JSON object : View
Products Affected
butterflymedia
- butterfly_organizer
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')