Multiple cross-site scripting (XSS) vulnerabilities in (1) start_page.css.php3 (aka start-page.css.php3) or (2) style.css.php3 in PHPMyChat 0.14.5 allow remote attackers to inject arbitrary web script or HTML commands via the FontName parameter. NOTE: it was later reported that 0.14.5 is also affected.
References
Configurations
Information
Published : 2005-05-15 21:00
Updated : 2018-10-19 08:31
NVD link : CVE-2005-1619
Mitre link : CVE-2005-1619
JSON object : View
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Products Affected
phpheaven
- phpmychat