Description
Incomplete blacklist in sanitize_string in Zenphoto before 1.4.9 allows remote attackers to conduct cross-site scripting (XSS) attacks.
Remediation
References
Related Vulnerabilities
PHP Improper Input Validation Vulnerability (CVE-2006-7243)
WordPress 'press-this.php' Remote Security Bypass Vulnerability (0.7 - 3.1.1)
WordPress Plugin SiteGround Security Security Bypass (1.2.4)
Resin Application Server Improper Input Validation Vulnerability (CVE-2012-2965)
WordPress Plugin Total Security Multiple Unspecified Vulnerabilities (3.4.1)