Vulnonym.org

CVE-2008-2758 - Tribunitial Fatigue

Description

Multiple cross-site scripting (XSS) vulnerabilities in Xigla Absolute News Manager XE 3.2 allow remote authenticated administrators to inject arbitrary web script or HTML via the (1) pblname and (2) text parameters to (a) admin/search.asp (3) name parameter to (b) admin/publishers.asp and other unspecified vectors to (c) anmviewer.asp and (d) editarticleX.asp in admin/. NOTE: some of these details are obtained from third party information.

Reference

http://marc.info/?l=bugtraq&m=121322052622903&w=2 http://bugreport.ir/index.php?/41 http://www.securityfocus.com/bid/29672 http://secunia.com/advisories/30643 http://securityreason.com/securityalert/3950 https://exchange.xforce.ibmcloud.com/vulnerabilities/43042