Multiple cross-site scripting (XSS) vulnerabilities in demo.php in BeatificFaith Eprayer Alpha allow remote attackers to inject arbitrary web script or HTML via the SRC attribute of a SCRIPT element in the (1) Your name field and (2) Enter Prayer Request here field.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Eprayer | Beatificfaith | alpha (including) | alpha (including) |