Multiple cross-site scripting (XSS) vulnerabilities in pfSense 2 beta 4 allow remote attackers to inject arbitrary web script or HTML via (1) the id parameter in an olsrd.xml action to pkgedit.php, (2) the xml parameter to pkg.php, or the if parameter to (3) statusgraph.php or (4) interfaces.php, a different vulnerability than CVE-2008-1182 and CVE-2010-4246.