CVE-2012-2938
27.05.2012, 20:55
Multiple cross-site scripting (XSS) vulnerabilities in Travelon Express 6.2.2 allow remote attackers to inject arbitrary web script or HTML via the holiday name field to (1) holiday_add.php or (2) holiday_view.php.
Vendor | Product | Version |
---|---|---|
itechscripts | travelon_express | 6.2.2 |
𝑥
= Vulnerable software versions
References