Multiple cross-site scripting (XSS) vulnerabilities in GuppY 4.5.3a and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the pg parameter to printfaq.php, or the (2) Referer or (3) User-Agent HTTP headers, which are not properly handled by error.php.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 00:00
Type | Values Removed | Values Added |
---|---|---|
References | () http://secunia.com/advisories/16707 - Patch, Vendor Advisory | |
References | () http://www.freeguppy.org/download.php?lng=en - Patch | |
References | () http://www.freeguppy.org/thread.php?lng=en&pg=81882&fid=1&cat=200 - | |
References | () http://www.securityfocus.com/bid/14753 - Patch |
Information
Published : 2005-09-08 10:03
Updated : 2024-11-21 00:00
NVD link : CVE-2005-2853
Mitre link : CVE-2005-2853
CVE.ORG link : CVE-2005-2853
JSON object : View
Products Affected
guppy
- guppy
CWE