Multiple cross-site scripting (XSS) vulnerabilities in EvGenius Counter 3.4 and earlier allow remote attackers to inject arbitrary web script or HTML via the page parameter in (1) monthly.php and (2) daily.php.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Evgenius_counter | Evgenius | * | 3.4 (including) |