Cross-site scripting (XSS) vulnerability in addcomment.php in Bit 5 Blog 8.01 allows remote attackers to inject arbitrary web script or HTML via a javascript URI in an tag in the comment parameter, which strips most tags but not .
Name | Vendor | Start Version | End Version |
---|---|---|---|
Bit_5_blog | Bit_5_blog | 8.01 (including) | 8.01 (including) |