Cross-site scripting (CSS) vulnerability in error.asp for Plumtree Corporate Portal 3.5 through 4.5 allows remote attackers to execute arbitrary script on other clients via the Description parameter.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Plumtree_corporate_portal | Plumtree | 3.5 (including) | 3.5 (including) |
Plumtree_corporate_portal | Plumtree | 4.0 (including) | 4.0 (including) |
Plumtree_corporate_portal | Plumtree | 4.0_sp1 (including) | 4.0_sp1 (including) |
Plumtree_corporate_portal | Plumtree | 4.0i (including) | 4.0i (including) |
Plumtree_corporate_portal | Plumtree | 4.0i_sp1 (including) | 4.0i_sp1 (including) |
Plumtree_corporate_portal | Plumtree | 4.5 (including) | 4.5 (including) |