Description
A stored cross site scripting (XSS) vulnerability in phplist 3.5.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Configure categories" field under the "Categorise Lists" module.
Remediation
References
Related Vulnerabilities
OpenSSL Numeric Errors Vulnerability (CVE-2007-5135)
WordPress Plugin Subscribe Sidebar by Blubrry Cross-Site Scripting (1.3.1)
Apache HTTP Server Other Vulnerability (CVE-2010-0408)
WordPress Plugin NextGEN Gallery-WordPress Gallery Directory Traversal (2.1.9)
Oracle Application Server CVE-2008-0346 Vulnerability (CVE-2008-0346)