IBM Tivoli Access Manager for e-business is prone to multiple cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input.An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may let the attacker steal cookie-based authentication credentials and launch other attacks.
The IBM Tivoli Access Manager for e-business is prone to multiple cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input. An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may let the attacker steal cookie-based authentication credentials and launch other attacks.
w-Agora is prone to a local file-include vulnerability and a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.An attacker can exploit the local file-include vulnerability using directory-traversal strings to view and execute local files within the context of the webserver process. Information harvested may aid in further attacks.The attacker may leverage the cross-site scripting issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may let the attacker steal cookie-based authentication credentials and launch other attacks.
The WBBlog application is vulnerable to both XSS and SQL Injection attacks. The SQL Injection vulnerability can be exploited by sending a specially crafted request to the index.php file, allowing an attacker to execute arbitrary SQL commands. The XSS vulnerability can be exploited by injecting malicious code into the 'e_id' parameter of the viewentry page, potentially leading to session hijacking or defacement of the website.
pecio cms is prone to a cross-site scripting vulnerability because it fails to sufficiently sanitize user-supplied input. An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks.
Wiccle Web Builder CMS and iWiccle CMS Community Builder are prone to multiple cross-site scripting vulnerabilities because they fail to properly sanitize user-supplied input. An attacker may leverage these issues to execute arbitrary HTML and script code in the browser of an unsuspecting user in the context of the affected site. This may let the attacker steal cookie-based authentication credentials and launch other attacks.
The Creative Guestbook 1.0 portal allows an attacker to add a remote admin user and perform cross site scripting attacks. The portal can be downloaded from http://www.thecreativeheads.de/CreativeFiles/downloads.php. The vulnerability can be exploited by inserting malicious scripts in the Guestbook.php file. An example script is <script> alert (' dj7xpl ^_^ ') </script>.
The vulnerability in Microsoft Windows Mobile allows an attacker to crash a device running Windows Mobile, thereby denying service to legitimate users. It is also possible for the attacker to run arbitrary code, although this has not been confirmed.
The SQL Injection vulnerability in 4Site CMS allows an attacker to execute unauthorized actions on the database, potentially compromising the application and facilitating further attacks.