CVE-2009-2928
21.08.2009, 20:30
Cross-site scripting (XSS) vulnerability in login.php in TGS Content Management 0.x allows remote attackers to inject arbitrary web script or HTML via the previous_page parameter, a different vector than CVE-2008-6839.
| Vendor | Product | Version |
|---|---|---|
| tgs-cms | tgs_content_management | 0.1.6 |
| tgs-cms | tgs_content_management | 0.1.7 |
| tgs-cms | tgs_content_management | 0.2.0 |
| tgs-cms | tgs_content_management | 0.2.5 |
| tgs-cms | tgs_content_management | 0.2.5:r2 |
| tgs-cms | tgs_content_management | 0.2.5:r3 |
| tgs-cms | tgs_content_management | 0.3.0 |
| tgs-cms | tgs_content_management | 0.3.2 |
| tgs-cms | tgs_content_management | 0.3.2:r2 |
𝑥
= Vulnerable software versions