Cross-site scripting (XSS) vulnerability in Operation/User.pm in Plain Black WebGUI before 7.3.5 (beta) allows remote attackers to inject arbitrary web script or HTML via the username parameter during anonymous registration, a different vector than CVE-2007-0308. NOTE: it is possible that a separate WikiPage titles issue was also fixed.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Webgui | Plain_black | 6.3.0 (including) | 6.3.0 (including) |
Webgui | Plain_black | 6.4.0 (including) | 6.4.0 (including) |
Webgui | Plain_black | 6.5.0 (including) | 6.5.0 (including) |
Webgui | Plain_black | 6.5.1 (including) | 6.5.1 (including) |
Webgui | Plain_black | 6.5.2 (including) | 6.5.2 (including) |
Webgui | Plain_black | 6.5.3 (including) | 6.5.3 (including) |
Webgui | Plain_black | 6.5.4 (including) | 6.5.4 (including) |
Webgui | Plain_black | 6.5.5 (including) | 6.5.5 (including) |
Webgui | Plain_black | 6.5.6 (including) | 6.5.6 (including) |
Webgui | Plain_black | 6.6.0 (including) | 6.6.0 (including) |
Webgui | Plain_black | 6.6.1 (including) | 6.6.1 (including) |
Webgui | Plain_black | 6.6.2 (including) | 6.6.2 (including) |
Webgui | Plain_black | 6.6.3 (including) | 6.6.3 (including) |
Webgui | Plain_black | 6.6.4 (including) | 6.6.4 (including) |
Webgui | Plain_black | 6.6.5 (including) | 6.6.5 (including) |
Webgui | Plain_black | 6.7.0 (including) | 6.7.0 (including) |
Webgui | Plain_black | 6.7.1 (including) | 6.7.1 (including) |
Webgui | Plain_black | 6.7.2 (including) | 6.7.2 (including) |
Webgui | Plain_black | 6.7.3 (including) | 6.7.3 (including) |
Webgui | Plain_black | 6.7.4 (including) | 6.7.4 (including) |
Webgui | Plain_black | 6.7.5 (including) | 6.7.5 (including) |
Webgui | Plain_black | 6.7.6 (including) | 6.7.6 (including) |
Webgui | Plain_black | 6.8.1 (including) | 6.8.1 (including) |
Webgui | Plain_black | 6.8.2 (including) | 6.8.2 (including) |
Webgui | Plain_black | 6.8.3 (including) | 6.8.3 (including) |
Webgui | Plain_black | 6.8.4 (including) | 6.8.4 (including) |
Webgui | Plain_black | 6.8.5 (including) | 6.8.5 (including) |
Webgui | Plain_black | 6.8.6 (including) | 6.8.6 (including) |
Webgui | Plain_black | 7.2.3 (including) | 7.2.3 (including) |
Webgui | Plain_black | 7.3.4_beta (including) | 7.3.4_beta (including) |