Description
|
|
Multiple vulnerabilities have been identified in DotClear, which could be exploited by attackers to execute arbitrary scripting code. These issues are caused by input validation errors in the "ecrire/tools/thememng/index.php" and "ecrire/trackback.php" scripts when processing the "tool_url", "post_id" and "tb_content" variables, which could be exploited by attackers to cause arbitrary scripting code to be executed by the user's browser in the security context of an affected Web site.
|