Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Geeklog Calendar Event Form Script Injection Vulnerability

Geeklog does not sufficiently sanitize script code from form fields, making it prone to script injection attacks.

Attacker-supplied script code may potentially end up in webpages generated by Geeklog and will execute in the browser of a user who views such pages, in the security context of the website.







 

Privacy Statement
Copyright 2008, SecurityFocus