Cross-site scripting (XSS) vulnerability in parser.php in phpCMS 1.2.1 and earlier, with non-stealth and debug modes enabled, allows remote attackers to inject arbitrary web script or HTML via the file parameter.
| Software | From | Fixed in |
|---|---|---|
| phpcms / phpcms | 1.2.1 | 1.2.1.x |
| phpcms / phpcms | 1.2 | 1.2.x |
| phpcms / phpcms | 1.1.9 | 1.1.9.x |