Multiple cross-site scripting (XSS) vulnerabilities in index.php in vscripts (aka Kuba Kunkiewicz) [V]Book (aka VBook) 2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) autor, (2) www, (3) temat, and (4) tresc parameters.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Vbook | Vscripts | 2.0 (including) | 2.0 (including) |