Cross-site scripting (XSS) vulnerability in atl.cgi in AtlantForum 4.02 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) sch_allsubct, (2) before, and (3) ct parameters.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Atlantforum | Atlantpro.com | * | 4.02 (including) |