Cross-site scripting (XSS) vulnerability in Grayscale Blog 0.8.0, and possibly earlier versions, allows remote attackers to inject arbitrary web script or HTML via the comment fields to (1) scripts/addblog_comment.php and (2) detail.php.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Grayscale_blog | Grayscale | * | 0.8.0 (including) |