Cross-site scripting (XSS) vulnerability in OSWiki before 0.3.1 allows remote attackers to inject arbitrary web script or HTML via the username field to (1) list.rhtml or (2) show.rhtml.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Oswiki | Oswiki | * | 0.3 (including) |