Multiple cross-site scripting (XSS) vulnerabilities in VBzoom allow remote attackers to inject arbitrary web script and HTML via the (1) UserName parameter to profile.php or (2) UserID parameter to login.php.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Vbzoom | Vbzoom | * | * |