Cross-site scripting (CSS) vulnerability in error.asp for Plumtree Corporate Portal 3.5 through 4.5 allows remote attackers to execute arbitrary script on other clients via the Description parameter.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Plumtree_corporate_portal | Plumtree | 4.0i_sp1 | 4.0i_sp1 |
Plumtree_corporate_portal | Plumtree | 4.0_sp1 | 4.0_sp1 |
Plumtree_corporate_portal | Plumtree | 4.0i | 4.0i |
Plumtree_corporate_portal | Plumtree | 4.0 | 4.0 |
Plumtree_corporate_portal | Plumtree | 3.5 | 3.5 |
Plumtree_corporate_portal | Plumtree | 4.5 | 4.5 |