Multiple cross-site scripting (XSS) vulnerabilities in Sambar Server 6.1 Beta 2 on Windows, and possibly other versions on Linux, allow remote attackers to inject arbitrary web script or HTML via (1) the show parameter in show.asp and (2) the title parameter in showperf.asp.
| Name | Vendor | Start Version | End Version | 
|---|---|---|---|
| Sambar_server | Sambar | 6.1-beta2 (including) | 6.1-beta2 (including) |