Required CVE Record Information
Description
Cross-site scripting (XSS) vulnerability in Guests/Boots in AdminCP in Moxi9 PHPFox before 4 Beta allows remote attackers to inject arbitrary web script or HTML via the User-Agent header.
References 5 Total
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 5 Total
- seclists.org: 20141118 PHPFox XSS AdminCP mailing-listx_transferred
- exchange.xforce.ibmcloud.com: phpfox-cve20148469-xss(98727) vdb-entryx_transferred
- http://packetstormsecurity.com/files/129153/PHPFox-Cross-Site-Scripting.html x_transferred
- securityfocus.com: 71180 vdb-entryx_transferred
- exploit-db.com: 35274 exploitx_transferred