Cross-site scripting (XSS) vulnerability in add.php in Fire-Mouse Toplist 1.1 and earlier, when register_globals is enabled, allows remote attackers to inject arbitrary web script or HTML via the Seitenname parameter.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Fire-mouse_toplist | Fire-mouse | * | 1.1 (including) |