Cross-site scripting (XSS) vulnerability in the category module in pafiledb.php for paFileDB 3.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter, a vulnerability that is closely related to CVE-2004-1551.
Software | From | Fixed in |
---|---|---|
php_arena / pafiledb | 3.0 | 3.0.x |
php_arena / pafiledb | 3.0_beta_3.1 | 3.0_beta_3.1.x |
php_arena / pafiledb | 3.1 | 3.1.x |