Cross-site scripting vulnerability (XSS) in BadBlue Enterprise Edition and Personal Edition 1.7 and 1.7.2 allows remote attackers to execute arbitrary script as other users by injecting script into ext.dll ISAPI.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Badblue | Working_resources_inc. | enterprise_1.7.2 (including) | enterprise_1.7.2 (including) |
| Badblue | Working_resources_inc. | personal_1.7 (including) | personal_1.7 (including) |
| Badblue | Working_resources_inc. | personal_1.7.2 (including) | personal_1.7.2 (including) |