Multiple cross-site scripting (XSS) vulnerabilities in admin/header.php in Toms Gaestebuch 1.01 and previous versions allow remote malicious users to inject arbitrary web script or HTML via the (1) lang[adminseite], (2) lang[ueberschrift], or (3) einst[metachar] parameter, different vectors than CVE-2007-4711.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
toms-seiten.at toms gastenbuch 1.00 |
||
toms-seiten.at toms gastenbuch 1.01 |