PHPIDS before 20070703 does not properly handle setting the .text property of a SCRIPT element before its attachment to the DOM, which allows remote attackers to inject arbitrary web script.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Phpids |
Phpids |
* |
* |
References