Multiple PHPGroupWare HTML Injection Vulnerabilities

PHPGroupWare has been reported prone to multiple HTML injection vulnerabilities. The issues present themselves due to a lack of sufficient input validation performed on form fields used by PHPGroupWare modules. A malicious attacker may inject arbitrary HTML and script code using these form fields that may be incorporated into dynamically generated web content.


 

Privacy Statement
Copyright 2010, SecurityFocus