Cross-site scripting (XSS) vulnerability in popup.php in PHPKIT 1.6.03 through 1.6.1 allows remote attackers to execute arbitrary web script via the img parameter.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Phpkit | Phpkit | 1.6.1 (including) | 1.6.1 (including) |
| Phpkit | Phpkit | 1.6.02 (including) | 1.6.02 (including) |
| Phpkit | Phpkit | 1.6.03 (including) | 1.6.03 (including) |