Multiple cross-site scripting (XSS) vulnerabilities in The Address Book 1.04e allow remote attackers to inject arbitrary web script or HTML via Javascript events in the (1) email, (2) websites, and (3) groupAddName parameters in (a) save.php; the (4) errorMsg parameter in (b) index.php; and the (5) goTo and (6) search parameters in (c) search.php.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: flexera
Published:
Updated: 2024-08-07T19:14:47.626Z
Reserved: 2006-09-06T00:00:00
Link: CVE-2006-4577

No data.

Status : Modified
Published: 2006-12-31T05:00:00.000
Modified: 2024-11-21T00:16:17.667
Link: CVE-2006-4577

No data.