Description
|
|
(:Several cross-site scripting vulnerabilities were reported in Dotclear.:A remote attacker could exploit them by enticing their victim into following a specially crafted link in order to execute arbitrary JavaScript/HTML code.::These vulnerabilities are exploitable via the "q" and "link_type" parameters of the "admin/media.php" script page.::Proofs of concept are available.::The dotclear packages provided by Debian Jessie 8 are vulnerable.)
|