Cross-site scripting (XSS) vulnerability in parser.php in phpCMS 1.2.1 and earlier, with non-stealth and debug modes enabled, allows remote attackers to inject arbitrary web script or HTML via the file parameter.
Software | From | Fixed in |
---|---|---|
phpcms / phpcms | 1.1.9 | 1.1.9.x |
phpcms / phpcms | 1.2 | 1.2.x |
phpcms / phpcms | 1.2.1 | 1.2.1.x |