CVE Database
/

CVE-2006-1479

Back to search

CVE-2006-1479

Published: Mar 29, 2006

Modified: Aug 7, 2024

PUBLISHED

Description

Multiple cross-site scripting (XSS) vulnerabilities in Serge Rey gtd-php (aka Getting Things Done) 0.5 allow remote attackers to inject arbitrary web script or HTML via the Description field in (1) newProject.php, (2) newList.php, and (3) newWaitingOn.php; the Title field in (4) newProject.php, (5) newList.php, (6) newWaitingOn.php, (7) newChecklist.php, (8) newContext.php, and (9) newGoal.php; the (10) Category Name field in newCategory.php; the (11) listTitle field in listReport.php; the (12) projectName field in projectReport.php; and the (13) checklistTitle field in checklistReport.php.

VendorProductVersions

n/a

n/a

affected
n/a

References

ADV-2006-1203
vdb-entry
x_refsource_VUPEN
17366
vdb-entry
x_refsource_BID
24156
vdb-entry
x_refsource_OSVDB
24158
vdb-entry
x_refsource_OSVDB
24151
vdb-entry
x_refsource_OSVDB
gtdphp-multiple-scripts-xss(25553)
vdb-entry
x_refsource_XF
24154
vdb-entry
x_refsource_OSVDB
24153
vdb-entry
x_refsource_OSVDB
24149
vdb-entry
x_refsource_OSVDB
24150
vdb-entry
x_refsource_OSVDB
24152
vdb-entry
x_refsource_OSVDB
19512
third-party-advisory
x_refsource_SECUNIA
24155
vdb-entry
x_refsource_OSVDB
24157
vdb-entry
x_refsource_OSVDB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now