Cross-site scripting (XSS) vulnerability in the category module in pafiledb.php for paFileDB 3.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter, a vulnerability that is closely related to CVE-2004-1551.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Pafiledb | Php_arena | 3.0 (including) | 3.0 (including) |
| Pafiledb | Php_arena | 3.0_beta_3.1 (including) | 3.0_beta_3.1 (including) |
| Pafiledb | Php_arena | 3.1 (including) | 3.1 (including) |