CVE-2008-1174

Properties

Published:
04.03.2008
Updated:
06.03.2008
Patch available:
Severity:
Medium
CVSS vector:
(AV:N/AC:M/Au:N/C:N/I:P/A:N)
Product:
Flicks Software: Authentix

Vulnerability description

Cross-site scripting (XSS) vulnerability in editUser.asp in AuthentiX 6.3b1 Trial allows remote attackers to inject arbitrary web script or HTML via the username parameter.

References:

FULLDISC: http://marc.info/?l=full-disclosure&m=120410229721185&w=2
BID: http://www.securityfocus.com/bid/28040
SECTRACK: http://securitytracker.com/id?1019520
SECUNIA: http://secunia.com/advisories/29142