Multiple cross-site scripting (XSS) vulnerabilities in hlstats.php in HLstats 1.35, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) authusername or (2) authpassword parameter, different vectors than CVE-2007-0840 and CVE-2007-2812.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: mitre
Published: 2007-05-24T18:00:00
Updated: 2024-08-07T13:57:53.726Z
Reserved: 2007-05-24T00:00:00
Link: CVE-2007-2847

No data.

Status : Deferred
Published: 2007-05-24T18:30:00.000
Modified: 2025-04-09T00:30:58.490
Link: CVE-2007-2847

No data.