Description
Multiple cross-site scripting (XSS) vulnerabilities in Belchior Foundry vCard 2.9 allow remote attackers to inject arbitrary web script or HTML via the page parameter in (1) toprated.php and (2) newcards.php. NOTE: the card_id vector is already covered by CVE-2006-1230.
Affected products
- belchior_foundry / vcard2.9 – 2.9
References
- MISChttp://securityreason.com/securityalert/1034
- MISChttps://exchange.xforce.ibmcloud.com/vulnerabilities/26838
- MISChttp://securitytracker.com/id?1016183
- MISChttp://www.securityfocus.com/archive/1/435310/100/0/threaded
- VENDOR_ADVISORYhttp://secunia.com/advisories/19216
- MISChttp://securityreason.com/securityalert/571