CVE

Id
32763  
CVE No.
CVE-2008-2646  
Status
Candidate  
Description
Multiple cross-site scripting (XSS) vulnerabilities in meBiblio 0.4.7 allow remote attackers to inject arbitrary web script or HTML via the (1) sql parameter to dbadd.inc.php, (2) InsertJournal parameter to add_journal_mask.inc.php, (3) InsertBibliography parameter to insert_mask.inc.php, and (4) LabelYear parameter to search_mask.inc.php.  
Phase
Assigned (20080610)  
Votes
None (candidate not yet proposed)  
Comments