Description
|
|
Multiple vulnerabilities were identified in Faq-O-Matic, which may be exploited by attackers to inject malicious HTML code. These flaws are due to input validation errors in the "fom.cgi" script that does not properly validate the "_duration", "file" and "cmd" parameters, which may be exploited by attackers to cause arbitrary scripting code to be executed by the user's browser in the security context of an affected Web site.
|