Cross-site scripting (XSS) vulnerability in AWFFull before 3.7.4, when AllSearchStr (aka the All Search Terms report) is enabled, allows remote attackers to inject arbitrary web script or HTML via a search string.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Awffull | Awffull | * | 3.7.1 (including) |
Awffull | Ubuntu | feisty | * |