| OSVDB ID | Disclosure Date | Title |
|
35337
Description:
CallManager contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'pattern' variable upon submission to the serverlist.asp script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2007-05-23
|
Cisco CallManager CCMAdmin/serverlist.asp pattern Parameter XSS
|
|
33895
Description:
ePortfolio contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate unspecified variables upon submission to the unspecified script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2007-03-08
|
ePortfolio Multiple Unspecified XSS
|
|
33896
Description:
ePortfolio contains a flaw that allows a remote Cross-Site Request Forgery (CSRF / XSRF) attack. The flaw exists because the application does not require multiple steps and/or confirmation for sensitive transactions for the unspecified functionality. By using a crafted URL (e.g. a crafted GET request inside an "img" tag), an attacker may trick the victim into clicking on the image to take advantage of the trust relationship between the authenticated victim and the application. Such an attack could trick the victim into executing arbitrary commands in the context of their session with the application, without further prompting or verification.
|
2007-03-08
|
ePortfolio Multiple Unspecified CSRF
|