Cross-site scripting (XSS) vulnerability in public/code/cpdpage.php in All In One Control Panel (AIOCP) before 1.3.017 allows remote attackers to inject arbitrary web script or HTML via the aiocpdp parameter. NOTE: some of these details are obtained from third party information.
Dynamic variable evaluation vulnerability in shared/config/cpconfig.php in All In One Control Panel (AIOCP) before 1.3.016 allows remote attackers to conduct cross-site scripting (XSS) and possibly other attacks via the SERVER superglobal array. NOTE: some of these details are obtained from third party information.
Cross-site scripting (XSS) vulnerability in shared/code/cpauthorization.php in All In One Control Panel (AIOCP) before 1.3.016 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters. NOTE: some of these details are obtained from third party information.