Cross-site scripting (XSS) vulnerability in install/default/error404.html in Oh no! Not another CMS (Onnac) 0.0.8.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the error_url parameter.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Oh_no_not_another_cms | Oh_no_not_another_cms | 0.0.8.4 (including) | 0.0.8.4 (including) |