|
Description
|
|
Multiple vulnerabilities have been identified in H-Sphere, which may be exploited by attackers to execute arbitrary scripting code. These flaws are due to input validation errors in the "mailman/massmail.html" script that does not validate the "next_template", "start", "curr_menu_id", and "arid" parameters, which could be exploited by attackers to cause arbitrary scripting code to be executed by the user's browser in the security context of an affected Web site.
|