PHP Volunteer Management Arbitrary File Upload and HTML Injection Vulnerabilities
15 Jun. 2012
Summary
PHP Volunteer Management is prone to an arbitrary-file-upload vulnerability and an HTML-injection vulnerability because it fails to properly sanitize user-supplied input.
An attacker could exploit these vulnerabilities to execute arbitrary script code in a user's browser in the context of the affected site or execute arbitrary code on the server.
Vendor Status:
Currently we are not aware of any vendor-supplied patches.