Cross-site scripting (XSS) vulnerability in pagesUTF8/auftrag_allgemeinauftrag.jsp in Plunet BusinessManager 4.1 and earlier allows remote authenticated users to inject arbitrary web script or HTML via the (1) QUB and (2) Bez74 parameters.
References
Configurations
History
No history.
Information
Published : 2009-02-23 15:30
Updated : 2024-02-04 17:33
NVD link : CVE-2009-0699
Mitre link : CVE-2009-0699
CVE.ORG link : CVE-2009-0699
JSON object : View
Products Affected
plunet
- business_manager
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')