Multiple cross-site scripting (XSS) vulnerabilities in...
        
  Low severity
        
          Unreviewed
      
        Published
          May 1, 2022 
          to the GitHub Advisory Database
          •
          Updated Jan 31, 2023 
      
  
Description
        Published by the National Vulnerability Database
      May 23, 2006 
    
  
        Published to the GitHub Advisory Database
      May 1, 2022 
    
  
        Last updated
      Jan 31, 2023 
    
  
Multiple cross-site scripting (XSS) vulnerabilities in Xtreme Topsites 1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter in stats.php and (2) unspecified inputs in lostid.php, probably the searchthis parameter. NOTE: one or more of these vectors might be resultant from SQL injection.
References