Cross-site scripting (XSS) vulnerability in Bug Report 1.0 allows remote attackers to inject arbitrary web script or HTML via various fields to bug_report.php, which are not filtered or quoted when processed by bug_list.php or admin/index.php.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Bug_report | Eric_fichot | 1.0 (including) | 1.0 (including) |