Cross-site scripting (XSS) vulnerability in error.php in NetRisk 2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the error parameter to index.php. NOTE: some of these details are obtained from third party information.
Software | From | Fixed in |
---|---|---|
netrisk / netrisk | - | 2.0.x |
netrisk / netrisk | 1.9.7 | 1.9.7.x |