CVE-2008-3715
19.08.2008, 19:41
Cross-site scripting (XSS) vulnerability in inc-core-admin-editor-previouscolorsjs.php in the FlexCMS 2.5 and earlier, when register_globals is enabled, allows remote attackers to inject arbitrary web script or HTML via the PreviousColorsString parameter.
Vendor | Product | Version |
---|---|---|
flexcms | flexcms | 2.0 |
flexcms | flexcms | 2.5 |
𝑥
= Vulnerable software versions
References