CVE-2012-4336
Multiple cross-site scripting (XSS) vulnerabilities in index.php in Flogr 2.5.6 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the PATH_INFO or (2) an arbitrary parameter.
Date published : 2012-09-15
http://www.securityfocus.com/bid/55418
http://archives.neohapsis.com/archives/bugtraq/2012-09/0021.html
