CVE-2009-0862
10.03.2009, 14:30
Cross-site scripting (XSS) vulnerability in the hook_cntrlr_error_output function in modules/page/hooks/listeners.php in the admincp component in TangoCMS 2.2.x (aka Eagle) before 2.2.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: some of these details are obtained from third party information.
Vendor | Product | Version |
---|---|---|
tangocms | tangocms | 𝑥 ≤ 2.2.3 |
tangocms | tangocms | 1.0.6 |
tangocms | tangocms | 1.0.8 |
tangocms | tangocms | 1.0.8.1 |
tangocms | tangocms | 2.0.0 |
tangocms | tangocms | 2.0.1 |
tangocms | tangocms | 2.0.2 |
tangocms | tangocms | 2.0.3 |
tangocms | tangocms | 2.0.4 |
tangocms | tangocms | 2.0.5 |
tangocms | tangocms | 2.0.6 |
tangocms | tangocms | 2.1.0 |
tangocms | tangocms | 2.1.1 |
tangocms | tangocms | 2.1.2 |
tangocms | tangocms | 2.2.0 |
tangocms | tangocms | 2.2.1 |
tangocms | tangocms | 2.2.2 |
𝑥
= Vulnerable software versions
References