Cross-Site Scripting Flaw in FlatPress by FlatPress
CVE-2008-4120

Currently unrated

Key Information:

Vendor

Flatpress

Status
Vendor
CVE Published:
29 September 2008

What is CVE-2008-4120?

Multiple cross-site scripting (XSS) vulnerabilities are present in FlatPress version 0.804, which enable remote attackers to exploit user and pass parameters in login.php and the name parameter in contact.php. By crafting malicious inputs, attackers can inject arbitrary web scripts or HTML, potentially compromising user data and the integrity of the website.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.