Multiple cross-site scripting (XSS) vulnerabilities in admin/actions.php in PHP-Blogger 2.2.5, and possibly earlier versions, allow remote attackers to execute arbitrary web script or HTML via the (1) name, (2) title, (3) news, (4) description, and (5) sitename parameters.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Php-blogger | Phpblogger | 2.2.5 (including) | 2.2.5 (including) |