CVE-2008-6700

Multiple cross-site scripting (XSS) vulnerabilities in Butterfly Organizer 2.0.0 allow remote attackers to inject arbitrary web script or HTML via the (1) mytable parameter to view.php, (2) mytable parameter to viewdb2.php, (3) tablehere parameter to category-rename.php, and (4) letter parameter to module-contacts.php.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:butterflymedia:butterfly_organizer:2.0.0:*:*:*:*:*:*:*

Information

Published : 2009-04-10 15:00

Updated : 2017-09-28 18:33


NVD link : CVE-2008-6700

Mitre link : CVE-2008-6700


JSON object : View

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Advertisement

dedicated server usa

Products Affected

butterflymedia

  • butterfly_organizer