Description
Projectsend version r1295 is affected by Cross Site Scripting (XSS) due to lack of sanitization when echo output data in returnFilesIds() function. A low privilege user can call this function through process.php file and execute scripting code.
Remediation
References
Related Vulnerabilities
WordPress Other Vulnerability (CVE-2004-1584)
Serendipity Other Vulnerability (CVE-2005-1713)
WordPress Plugin All-in-One Event Calendar Cross-Site Scripting (2.5.38)
WordPress Plugin Media Tagz Gallery Multiple Unspecified Vulnerabilities (1.0)
WordPress Plugin NextGEN Gallery-WordPress Gallery Remote Code Execution (2.1.59)