CVE-2009-1070
26.03.2009, 05:51
Cross-site scripting (XSS) vulnerability in system/index.php in ExpressionEngine 1.6.4 through 1.6.6, and possibly earlier versions, allows remote attackers to inject arbitrary web script or HTML via the avatar parameter.
Vendor | Product | Version |
---|---|---|
expressionengine | expressionengine | 1.6.4 |
expressionengine | expressionengine | 1.6.5 |
expressionengine | expressionengine | 1.6.6 |
𝑥
= Vulnerable software versions
References