Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
BugTraq
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
Liferay Enterprise Portal multiple XSS Nov 27 2007 08:20PM
morin josh gmail com
Vendor Site: Liferay.net

Version affected: Liferay Enterprise Portal 4.3.1

Demo:http://www.liferay.net/c/portal/login?tabs1=forgot-password

Class: Input Validation Error

Overview: Liferay fails to sufficiently sanitize user-supplied input data in "email address" text box by pressing the "Send...

[ more ]  





 

Privacy Statement
Copyright 2009, SecurityFocus