Vulnonym.org

CVE-2008-1850 - Authorisable Tourist

Description

Multiple cross-site scripting (XSS) vulnerabilities in login.php in Omnistar Interactive OSI Affiliate allow remote attackers to inject arbitrary web script or HTML via the (1) login (2) profile (3) profile2 and (4) ref parameters.

Reference

http://www.mrzayas.es/2008/04/11/xss-en-osiaffiliate/ http://secunia.com/advisories/29779 http://www.securityfocus.com/bid/28785 http://www.securityfocus.com/bid/28793 http://www.osvdb.org/44376 https://exchange.xforce.ibmcloud.com/vulnerabilities/41825 https://exchange.xforce.ibmcloud.com/vulnerabilities/41811