| HIO-2009-1123 PHPizabi Multiple Vulnerabilities |
|
|
|
|
PHPizabi 0.848b C1 HFP1 and earlier contains multiple flaws that allow cross-site scripting and cross-site request forgery. 1) XSS: Input passed via various parameters to multiple scripts is not properly sanitised before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site. References: CVE-2009-pending FrSIRT: N/A Nessus:N/A OSVDB: SA: 34396 XF: Related: Vendor Solution: |
| < Prev | Next > |
|---|







