Discovered by Andrew Bick on behalf of The Missing Link Security
XMLRPC-C Library versions 1.07 through 1.67.01 are vulnerable to a reflected cross-site scripting (XSS) vulnerability in the error page component. Under specific conditions, this may allow an adversary to hijack a victim user’s session and perform actions in their security context.
Affected Versions
1.07 to 1.67.01 (Advanced and Stable branches)
1.07 to 1.64.03 (Super Stable branch)
Fixed Versions
1.67.02 (Advanced and Stable branches)
1.64.04 (Super Stable branch)