1 results (0.004 seconds)

CVSS: 6.1EPSS: 4%CPEs: 1EXPL: 3

17 Nov 2014 — Multiple cross-site scripting (XSS) vulnerabilities in phpSound 1.0.5 allow remote attackers to inject arbitrary web script or HTML via the (1) Title or (2) Description fields in a playlist or the (3) filter parameter in an explore action to index.php. Múltiples vulnerabilidades de XSS en phpSound 1.0.5 permiten a atacantes remotos inyectar secuencias de comandos web o HTML arbitrarios a través de los campos (1) Título o (2) Descripción o el parámetro (3) filter en una exploración en index.php. • https://www.exploit-db.com/exploits/35198 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •