Description
Cross-site scripting (XSS) vulnerability in preferences.php in PHP Address Book 7.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the from parameter. NOTE: the index.php vector is already covered by CVE-2008-2566.
Remediation
References
Related Vulnerabilities
WordPress Plugin GigPress 'Notes' Field HTML Injection (2.1.10)
WordPress Plugin Social Share Icons & Social Share Buttons Security Bypass (3.0.2)
MediaWiki Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2015-6727)
WordPress Plugin Link Library Cross-Site Scripting (5.9.5.5)