|
Input appended to the URL after admin/plugins/clear_cache.php is not properly sanitised in the "show_form_header()" function in admin/admin_functions.php before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.
|