RSS   Vulnerabilities for 'Edittag'   RSS

2007-01-08
 
CVE-2007-0119

CWE-Other
 

 
Multiple cross-site scripting (XSS) vulnerabilities in EditTag 1.2 allow remote attackers to inject arbitrary web script or HTML via the plain parameter to (1) mkpw_mp.cgi, (2) mkpw.pl, or (3) mkpw.cgi.

 
 
CVE-2007-0118

CWE-Other
 

 
Multiple absolute path traversal vulnerabilities in EditTag 1.2 allow remote attackers to read arbitrary files via an absolute pathname in the file parameter to (1) edittag.cgi, (2) edittag.pl, (3) edittag_mp.cgi, or (4) edittag_mp.pl.

 


Copyright 2024, cxsecurity.com

 

Back to Top