Description
The admin backend in phpMyFAQ before 2.9.11 allows CSV injection in reports.
Remediation
References
Related Vulnerabilities
Plone CMS Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2012-5488)
WordPress Plugin Attachment Manager Arbitrary File Upload (2.1.1)
WordPress Plugin Polo Video Gallery-Best wordpress video gallery Cross-Site Scripting (1.2)
WordPress Plugin Locatoraid Store Locator Cross-Site Request Forgery (3.9.11)