Search Results
There are 4 CVE entries that match your search.
| Name |
Description |
| CVE-2007-6001 |
Multiple cross-site scripting (XSS) vulnerabilities in index.php in
Bandersnatch 0.4 allow remote attackers to inject arbitrary web script
or HTML via the (1) func or (2) date parameter, or the jid parameter
in a (3) log or (4) user action, a different vulnerability than
CVE-2007-3910.
|
| CVE-2007-5942 |
Bandersnatch 0.4 allows remote attackers to obtain sensitive
information via a malformed request for index.php with (1) a certain
func parameter value; or (2) certain func, jid, page, and limit
parameter values; which reveals the path in various error messages.
|
| CVE-2007-3910 |
Cross-site scripting (XSS) vulnerability in Bandersnatch 0.4 allows
remote attackers to inject arbitrary JavaScript via a Jabber resource
name and possibly other data items, which are stored in conversation
logs.
|
| CVE-2007-3909 |
Multiple SQL injection vulnerabilities in Bandersnatch 0.4 allow
remote attackers to execute arbitrary SQL commands via the (1) date
and (2) limit parameters to index.php, and other unspecified vectors.
|