Cross-site scripting (XSS) vulnerability in showprofile.php in Darrens $5 Script Archive osDate 1.1.7 and earlier allows remote attackers to inject arbitrary web script or HTML via the onerror attribute in an HTML IMG tag with a non-existent source file in txtcomment parameter, which is used when posting a comment.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Osdate | Darrens_5-dollar_script_archive | * | 1.1.7 (including) |
Osdate | Darrens_5-dollar_script_archive | 1.1.5 (including) | 1.1.5 (including) |
Osdate | Darrens_5-dollar_script_archive | 1.1.6 (including) | 1.1.6 (including) |