Multiple cross-site scripting (XSS) vulnerabilities in index.inc.php in PHProxy before 0.5 beta 2 allow remote attackers to inject arbitrary web script or HTML via the (1) data[realm] and (2) _url parameters, different vectors than CVE-2004-2604. NOTE: some of these details are obtained from third party information.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Phproxy | Phproxy | 0.1 (including) | 0.1 (including) |
Phproxy | Phproxy | 0.2 (including) | 0.2 (including) |
Phproxy | Phproxy | 0.3 (including) | 0.3 (including) |
Phproxy | Phproxy | 0.4 (including) | 0.4 (including) |