Description
Cross-site scripting (XSS) vulnerability in phpMyFAQ before 2.6.9 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to index.php.
Remediation
References
Related Vulnerabilities
IBM RTC Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2015-0113)
ownCloud Permissions, Privileges, and Access Controls Vulnerability (CVE-2013-6403)
WordPress Plugin College publisher Import Arbitrary File Upload (0.1)
WordPress Plugin UpdraftPlus WordPress Backup Cross-Site Scripting (1.22.8)