Cross-site scripting (XSS) vulnerability in Comersus BackOffice allows remote attackers to inject arbitrary web script or HTML via the error parameter to comersus_backoffice_supportError.asp. NOTE: the comersus_backoffice_message.asp/message vector is already covered by CVE-2005-2191 item 2.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Comersus_backoffice_lite | Comersus_open_technologies | * | * |
Comersus_backoffice_lite | Comersus_open_technologies | 4.2 (including) | 4.2 (including) |
Comersus_backoffice_lite | Comersus_open_technologies | 4.5 (including) | 4.5 (including) |
Comersus_backoffice_lite | Comersus_open_technologies | 4.10 (including) | 4.10 (including) |
Comersus_backoffice_lite | Comersus_open_technologies | 4.11 (including) | 4.11 (including) |
Comersus_backoffice_lite | Comersus_open_technologies | 4.30 (including) | 4.30 (including) |
Comersus_backoffice_lite | Comersus_open_technologies | 4.32 (including) | 4.32 (including) |
Comersus_backoffice_lite | Comersus_open_technologies | 5.0 (including) | 5.0 (including) |
Comersus_backoffice_lite | Comersus_open_technologies | 5.0.9 (including) | 5.0.9 (including) |
Comersus_backoffice_lite | Comersus_open_technologies | 6.0 (including) | 6.0 (including) |
Comersus_backoffice_lite | Comersus_open_technologies | 6.0.1 (including) | 6.0.1 (including) |
Comersus_backoffice_plus | Comersus_open_technologies | * | * |
Comersus_backoffice_plus | Comersus_open_technologies | 4.2 (including) | 4.2 (including) |
Comersus_backoffice_plus | Comersus_open_technologies | 4.5 (including) | 4.5 (including) |
Comersus_backoffice_plus | Comersus_open_technologies | 4.10 (including) | 4.10 (including) |
Comersus_backoffice_plus | Comersus_open_technologies | 4.11 (including) | 4.11 (including) |
Comersus_backoffice_plus | Comersus_open_technologies | 4.30 (including) | 4.30 (including) |
Comersus_backoffice_plus | Comersus_open_technologies | 4.32 (including) | 4.32 (including) |
Comersus_backoffice_plus | Comersus_open_technologies | 5.0 (including) | 5.0 (including) |
Comersus_backoffice_plus | Comersus_open_technologies | 5.0.9 (including) | 5.0.9 (including) |
Comersus_backoffice_plus | Comersus_open_technologies | 6.0 (including) | 6.0 (including) |
Comersus_backoffice_plus | Comersus_open_technologies | 6.0.1 (including) | 6.0.1 (including) |