Multiple cross-site scripting (XSS) vulnerabilities in IT!CMS (itcms) 0.2 allow remote attackers to inject arbitrary web script or HTML via the wndtitle parameter to (1) lang-en.php, (2) menu-ed.php, or (3) titletext-ed.php.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Itcms | Itcms | 0.2 (including) | 0.2 (including) |