CVE-2010-1068
23.03.2010, 18:30
Multiple cross-site scripting (XSS) vulnerabilities in surgeftpmgr.cgi in NetWin SurgeFTP 2.3a6 allow remote attackers to inject arbitrary web script or HTML via the (1) domainid or (2) classid parameter in a class action.
| Vendor | Product | Version |
|---|---|---|
| netwin | surgeftp | 2.3a6:a6 |
𝑥
= Vulnerable software versions
References