inc/vul_check.inc in phpVideoPro before 0.8.8 permits non-alphanumeric characters in the sess_id parameter, which has unknown impact and remote attack vectors, probably cross-site scripting (XSS).
References
Configurations
History
No history.
Information
Published : 2007-07-06 18:30
Updated : 2025-04-09 00:30
NVD link : CVE-2007-3596
Mitre link : CVE-2007-3596
CVE.ORG link : CVE-2007-3596
JSON object : View
Products Affected
izzysoft
- phpvideopro
CWE