First published: Thu Apr 16 2009(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in web/guest/home in the Liferay 4.3.0 portal in Novell Teaming 1.0 through SP3 (1.0.3) allow remote attackers to inject arbitrary web script or HTML via the (1) p_p_state or (2) p_p_mode parameters.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Novell Teaming | =1.0 | |
Novell Teaming | =1.0.1 | |
Novell Teaming | =1.0.2 | |
Novell Teaming | =1.0.3 | |
Liferay Liferay Enterprise Portal | =4.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.