Cross-site scripting (XSS) vulnerability in app/helpers/application_helper.rb in Mephisto 0.7.3 and Mephisto Edge 20070325 allows remote attackers to inject arbitrary web script or HTML via the author name field in a comment.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Mephisto | Mephisto | 0.7.3 (including) | 0.7.3 (including) |
Mephisto_edge | Mephisto | 2007-03-25 (including) | 2007-03-25 (including) |