Multiple cross-site scripting (XSS) vulnerabilities in eyeOS before 0.9.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors involving (1) eyeNav and (2) system/baixar.php.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Eyeos | Eyeos_project | * | 0.9.0.6 (including) |
Eyeos | Eyeos_project | 0.8.3 (including) | 0.8.3 (including) |
Eyeos | Eyeos_project | 0.8.3_r2 (including) | 0.8.3_r2 (including) |
Eyeos | Eyeos_project | 0.8.4 (including) | 0.8.4 (including) |
Eyeos | Eyeos_project | 0.8.4_r1 (including) | 0.8.4_r1 (including) |
Eyeos | Eyeos_project | 0.8.5 (including) | 0.8.5 (including) |
Eyeos | Eyeos_project | 0.8.9 (including) | 0.8.9 (including) |
Eyeos | Eyeos_project | 0.8.10 (including) | 0.8.10 (including) |
Eyeos | Eyeos_project | 0.9.0.1 (including) | 0.9.0.1 (including) |
Eyeos | Eyeos_project | 0.9.0.2 (including) | 0.9.0.2 (including) |
Eyeos | Eyeos_project | 0.9.0.3 (including) | 0.9.0.3 (including) |
Eyeos | Eyeos_project | 0.9.0.4 (including) | 0.9.0.4 (including) |
Eyeos | Eyeos_project | 0.9.0.5 (including) | 0.9.0.5 (including) |