cleanhtml.pl 1.129 in LiveJournal CVS before Dec 13 2005 allows remote attackers to inject scripting languages via the XSL namespace in XML, via vectors such as customview.cgi.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Livejournal |
Livejournal |
* |
* |
References