inc/vul_check.inc in phpVideoPro before 0.8.8 permits non-alphanumeric characters in the sess_id parameter, which has unknown impact and remote attack vectors, probably cross-site scripting (XSS).
Name | Vendor | Start Version | End Version |
---|---|---|---|
Phpvideopro | Izzysoft | * | 0.8.7 (including) |