Cross-site scripting (XSS) vulnerability in htsrv/login.php in b2evolution 1.8.6 allows remote attackers to inject arbitrary web script or HTML via scriptable attributes in the redirectto parameter.
Multiple cross-site scripting (XSS) vulnerabilities in b2evolution 1.8.2 through 1.9 beta allow remote attackers to inject arbitrary web script or HTML via the (1) appname parameter in (a) 404notfound.page.php, (b) 410statsgone.page.php, and (c) refererspam.page.php in inc/VIEW/errors/; the (2) baseurl parameter in (d) inc/VIEW/errors/404notfound.page.php; and the (3) ReqURI parameter in (e) inc/VIEW/errors/refererspam.page.php.