Multiple cross-site scripting (XSS) vulnerabilities in LightNEasy "no database" (aka flat) version 1.2.2, and possibly SQLite version 1.2.2, allow remote attackers to inject arbitrary web script or HTML via the page parameter to (1) index.php and (2) LightNEasy.php.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2009-04-03 11:30
Updated : 2018-10-11 13:57
NVD link : CVE-2008-6589
Mitre link : CVE-2008-6589
JSON object : View
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Products Affected
sqlite
- sqlite
lightneasy
- lightneasy