Description
Cross-site scripting (XSS) vulnerability in wflogin.jsp in Aris Global ARISg 5.0 allows remote attackers to inject arbitrary web script or HTML via the errmsg parameter.
Affected products
- arisglobal / arisg5.0 – 5.0
References
- VENDOR_ADVISORYhttp://secunia.com/advisories/38793
- EXPLOIThttp://packetstormsecurity.org/1002-exploits/arisg5-xss.txt
- MISChttp://osvdb.org/62665
- MISChttp://www.securityfocus.com/archive/1/509758/100/0/threaded
- MISChttp://www.securityfocus.com/bid/38441
- MISChttp://www.securityfocus.com/archive/1/509770/100/0/threaded