CVE-2009-2569

Publication date 22 July 2009

Last updated 24 July 2024


Ubuntu priority

Description

Multiple cross-site scripting (XSS) vulnerabilities in Verlihub Control Panel (VHCP) 1.7e allow remote attackers to inject arbitrary web script or HTML via (1) the nick parameter in a login action to index.php or (2) the URI in a news request to index.html.

Read the notes from the security team

Status

Package Ubuntu Release Status
verlihub 11.10 oneiric Not in release
11.04 natty Not in release
10.10 maverick Not in release
10.04 LTS lucid Not in release
9.10 karmic Not in release
9.04 jaunty Ignored end of life
8.10 intrepid Ignored end of life, was needs-triage
8.04 LTS hardy Ignored end of life
6.06 LTS dapper Not in release

Notes


mdeslaur

PoC: http://packetstorm.linuxsecurity.com/0905-exploits/verlihub-xss.txt