CVE-2009-2928
21.08.2009, 20:30
Cross-site scripting (XSS) vulnerability in login.php in TGS Content Management 0.x allows remote attackers to inject arbitrary web script or HTML via the previous_page parameter, a different vector than CVE-2008-6839.
Vendor | Product | Version |
---|---|---|
tgs-cms | tgs_content_management | 0.1.6 |
tgs-cms | tgs_content_management | 0.1.7 |
tgs-cms | tgs_content_management | 0.2.0 |
tgs-cms | tgs_content_management | 0.2.5 |
tgs-cms | tgs_content_management | 0.2.5:r2 |
tgs-cms | tgs_content_management | 0.2.5:r3 |
tgs-cms | tgs_content_management | 0.3.0 |
tgs-cms | tgs_content_management | 0.3.2 |
tgs-cms | tgs_content_management | 0.3.2:r2 |
𝑥
= Vulnerable software versions