Multiple cross-site scripting vulnerabilities exist in WackoWiki. The vendor has released a fixed version to address these issues but has not provided any further information regarding these issues. The issues may likely be exploited to steal cookie-based authentication credentials. Other attacks may also be possible. The vulnerabilities are reported to affect WackoWiki R4. It is not known if earlier versions are also affected. These issues are distinct from the vulnerabilities reported in BID 11935 "WackoWiki Multiple Unspecified Cross-Site Scripting Vulnerabilities".
Multiple cross-site scripting vulnerabilities exist in WackoWiki. The vendor has released a fixed version to address these issues but has not provided any further information regarding these issues. The issues may likely be exploited to steal cookie-based authentication credentials. Other attacks may also be possible. The vulnerabilities are reported to affect WackoWiki R4. It is not known if earlier versions are also affected. These issues are distinct from the vulnerabilities reported in BID 11935 "WackoWiki Multiple Unspecified Cross-Site Scripting Vulnerabilities".