Security Advisory

CVE-2010-3690

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2010-10-07 20:21:00
Last updated 2024-08-07 03:18:52
Assigner redhat
State PUBLISHED

Description

Multiple cross-site scripting (XSS) vulnerabilities in phpCAS before 1.1.3, when proxy mode is enabled, allow remote attackers to inject arbitrary web script or HTML via (1) a crafted Proxy Granting Ticket IOU (PGTiou) parameter to the callback function in client.php, (2) vectors involving functions that make getCallbackURL calls, or (3) vectors involving functions that make getURL calls.