Vulnerabilities (CVE)

Filtered by vendor Phpslideshow Subscribe
Filtered by product Phpslideshow
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2007-6135 1 Phpslideshow 1 Phpslideshow 2024-02-04 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in phpslideshow.php in PHPSlideShow 0.9.9.2, and possibly earlier, allows remote attackers to inject arbitrary web script or HTML via the directory parameter. NOTE: this issue was originally reported for toonchapter8.php, but this is probably a site-specific name, since the PHPSlideShow distribution does not contain that file.