Incomplete blacklist vulnerability in the stripScripts function in common.php in OneOrZero Helpdesk 1.6.5.4, 1.6.4.2, and possibly other versions, allows remote attackers to conduct cross-site scripting (XSS) attacks and inject arbitrary web script or HTML via XSS sequences without SCRIPT tags in the description parameter to (1) tcreate.php or (2) tupdate.php, as demonstrated using an onmouseover event in a b tag.
                
            Metrics
Affected Vendors & Products
References
        History
                    No history.
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: mitre
Published: 2007-10-30T21:00:00
Updated: 2024-08-07T15:39:13.699Z
Reserved: 2007-10-30T00:00:00
Link: CVE-2007-5727
 Vulnrichment
                        Vulnrichment
                    No data.
 NVD
                        NVD
                    Status : Deferred
Published: 2007-10-30T21:46:00.000
Modified: 2025-04-09T00:30:58.490
Link: CVE-2007-5727
 Redhat
                        Redhat
                    No data.
 ReportizFlow
ReportizFlow