Cross-site scripting (XSS) vulnerability in adframe.php in phpAdsNew 2.0.4-pr1, when register_globals is enabled, allows remote attackers to inject arbitrary web script or HTML via the refresh parameter.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.043
EPSS Ranking 88.6%