inc/vul_check.inc in phpVideoPro before 0.8.8 permits non-alphanumeric characters in the sess_id parameter, which has unknown impact and remote attack vectors, probably cross-site scripting (XSS).
References
Configurations
Information
Published : 2007-07-06 11:30
Updated : 2017-07-28 18:32
NVD link : CVE-2007-3596
Mitre link : CVE-2007-3596
JSON object : View
CWE
Products Affected
izzysoft
- phpvideopro