Multiple cross-site scripting (XSS) vulnerabilities in hlstats.php in HLstats 1.35, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) authusername or (2) authpassword parameter, different vectors than CVE-2007-0840 and CVE-2007-2812.
References
Configurations
History
No history.
Information
Published : 2007-05-24 18:30
Updated : 2024-02-04 17:13
NVD link : CVE-2007-2847
Mitre link : CVE-2007-2847
CVE.ORG link : CVE-2007-2847
JSON object : View
Products Affected
hlstats
- hlstats
CWE