CVE

Id
32013  
CVE No.
CVE-2008-1896  
Status
Candidate  
Description
Multiple cross-site scripting (XSS) vulnerabilities in Carbon Communities 2.4 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) Redirect parameter to login.asp and the (2) OrderBy parameter to member_send.asp.  
Phase
Assigned (20080418)  
Votes
None (candidate not yet proposed)  
Comments