VYPR

ScareCrow

by ScareCrow

CVEs (1)

  • CVE-2005-4307Dec 17, 2005
    risk 0.03cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in ScareCrow 2.13 and earlier allows remote attackers to inject arbitrary web script or HTML via the forum parameter to (1) forum.cgi and (2) post.cgi, or (3) the user parameter to profile.cgi.