Description
Multiple cross-site scripting (XSS) vulnerabilities in Zikula Application Framework 1.2.2, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) func parameter to index.php, or the (2) lang parameter to index.php, which is not properly handled by ZLanguage.php.
Remediation
References
Related Vulnerabilities
WordPress Plugin Party Hall Booking Manager SQL Injection (1.1)
WordPress Plugin SP Rental Manager SQL Injection (1.5.3)
Zope Web Application Server Other Vulnerability (CVE-2001-1278)
WordPress Plugin Video Gallery-Vimeo and YouTube Gallery Cross-Site Scripting (1.1.4)
WordPress Plugin Weather Effect-Christmas Santa Snow Falling Cross-Site Scripting (1.3.5)