Multiple cross-site scripting (XSS) vulnerabilities in search.php in Banana Dance, possibly B.1.5 and previous versions, allow remote malicious users to inject arbitrary web script or HTML via the (1) q or (2) category parameter.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
bananadance banana dance |
||
bananadance banana dance 0.9 |