Vulnonym.org

CVE-2008-1630 - Gorilloid Poet

Description

Multiple cross-site scripting (XSS) vulnerabilities in CuteFlow 1.5.0 and 2.10.0 allow remote attackers to inject arbitrary web script or HTML via the language parameter to (1) page/showcirculation.php; and (2) edittemplate_step2.php (3) showfields.php (4) showuser.php (5) editmailinglist_step1.php and (6) showtemplates.php in pages/.

Reference

http://www.securityfocus.com/bid/28500 http://secunia.com/advisories/29612 http://securityreason.com/securityalert/3792 https://exchange.xforce.ibmcloud.com/vulnerabilities/41537 http://www.securityfocus.com/archive/1/490305/100/0/threaded