CVE-2007-3653 Information

Description

Multiple cross-site scripting (XSS) vulnerabilities in Farsi Script (aka FaScript) FaName 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) key or (2) desc parameter to index.php or (3) the name parameter to page.php.

Reference

http://descriptions.securescout.com/tc/17973 http://www.netvigilance.com/advisory0043 https://exchange.xforce.ibmcloud.com/vulnerabilities/43502

Share on: