Description
TCExam before 14.1.2 has XSS via an ff_ or xl_ field.
Remediation
References
Related Vulnerabilities
WordPress Plugin Event Management Tickets Booking By Event Monster Cross-Site Scripting (1.0.7)
Apache HTTP Server Other Vulnerability (CVE-2004-0493)
Moodle Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2008-3325)
WordPress Plugin Donate by BestWebSoft Cross-Site Scripting (2.0.1)
phpBB Permissions, Privileges, and Access Controls Vulnerability (CVE-2010-1627)