Description
Cross-site scripting (XSS) vulnerability in tasks.php in WebCollab before 2.50 (aka Billy Goat) allows remote attackers to inject arbitrary web script or HTML via the selection parameter in a todo action.
Affected products
- andrew_simpson / webcollab2.40
- andrew_simpson / webcollab2.20 – 2.20
- andrew_simpson / webcollab2.30 – 2.30
- andrew_simpson / webcollab2.31 – 2.31
References
- MISChttps://exchange.xforce.ibmcloud.com/vulnerabilities/49939
- VENDOR_ADVISORYhttp://secunia.com/advisories/34568
- MISChttp://www.osvdb.org/53780
- MISChttp://holisticinfosec.org/content/view/108/45/
- MISChttp://sourceforge.net/project/shownotes.php?release_id=676245&group_id=75945
- MISChttp://www.securityfocus.com/bid/34576