Cross-site scripting (XSS) vulnerability in ecrire/tools.php in DotClear 1.2.6 allows remote attackers to inject arbitrary web script or HTML via unspecified form fields on the blogroll page.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Dotclear | Dotclear | 1.2.6 (including) | 1.2.6 (including) |