Multiple cross-site scripting (XSS) vulnerabilities in IntranetApp 3.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) ret_page parameter to login.asp or the (2) do_search and (3) search parameters to content.asp.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Intranetapp | Iatek | * | 3.3 (including) |