Cross-site scripting (XSS) vulnerability in the category page in VCD-db 0.98 and earlier allows remote attackers to inject arbitrary web script or HTML via the batch parameter.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Vcd-db | Vcd-db | 0.97 (including) | 0.97 (including) |
Vcd-db | Vcd-db | 0.98 (including) | 0.98 (including) |
Vcd-db | Vcd-db | 0.961 (including) | 0.961 (including) |
Vcd-db | Vcd-db | 0.971 (including) | 0.971 (including) |
Vcd-db | Vcd-db | 0.972 (including) | 0.972 (including) |
Vcd-db | Vcd-db | 0.973 (including) | 0.973 (including) |