Cross-site scripting (XSS) vulnerability in the category module in pafiledb.php for paFileDB 3.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter, a vulnerability that is closely related to CVE-2004-1551.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Pafiledb | Php_arena | 3.0 (including) | 3.0 (including) |
Pafiledb | Php_arena | 3.0_beta_3.1 (including) | 3.0_beta_3.1 (including) |
Pafiledb | Php_arena | 3.1 (including) | 3.1 (including) |