CVE

Id
13205  
CVE No.
CVE-2005-1999  
Status
Candidate  
Description
Multiple cross-site scripting (XSS) vulnerabilities in pafiledb.php in paFileDB 3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) sortby or (2) filelist parameters to the category action (category.php), or (3) pages parameter in the viewall action (viewall.php).  
Phase
Assigned (20050620)  
Votes
None (candidate not yet proposed)  
Comments