Cross-site scripting (XSS) vulnerability in search.php in Sphider 1.3.4, when the search suggestion feature is enabled, allows remote malicious users to inject arbitrary web script or HTML via the query parameter, a different vector than CVE-2006-2506.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
sphider sphider 1.3.4 |