Cross-site scripting (XSS) vulnerability in updir.php in UPDIR.NET before 2.04 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.Referenceshttp://osvdb.org/38787http://jvn.jp/jp/JVN%2399453765/index.htmlhttp://www.securityfocus.com/bid/26394http://secunia.com/advisories/27581http://updir.net/osirase.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/38364