Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

mnoGoSearch Multiple Cross-Site Scripting Vulnerabilities

It is reported that mnoGoSearch is affected by various cross-site scripting vulnerabilities. These issues are due to a failure of the application to properly sanitize user-supplied URI input.

These problems present themselves when malicious HTML and script code is sent to the application through the next/prev search results page and extended/simple search form links.

mnoGoSearch 3.2.26 and prior versions are vulnerable to these issues.







 

Privacy Statement
Copyright 2008, SecurityFocus