Description
|
|
Multiple vulnerabilities were identified in ProjectApp, which may be exploited by attackers to inject malicious HTML code. These flaws are due to input validation errors in the "forums.asp", "search_employees.asp", "cat.asp", "links.asp", "pmprojects.asp", "login.asp" and "default.asp" scripts that do not properly validate the "keywords", "projectid", "ret_page" and "skin_number" parameters, which may be exploited by attackers to cause arbitrary scripting code to be executed by the user's browser in the security context of an affected Web site.
|