Cross-site scripting (XSS) vulnerability in ecrire/tools.php in DotClear 1.2.6 allows remote attackers to inject arbitrary web script or HTML via unspecified form fields on the blogroll page.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Dotclear | Dotclear | 1.2.6 (including) | 1.2.6 (including) |