Описание
Multiple cross-site scripting (XSS) vulnerabilities in XOOPS 2.0.11 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) order parameter to edit.php or (2) cid parameter to comment_edit.php.
Ссылки
- ExploitPatchVendor Advisory
- Patch
- ExploitPatchVendor Advisory
- Patch
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:a:xoops:xoops:2.0:*:*:*:*:*:*:*
cpe:2.3:a:xoops:xoops:2.0.1:*:*:*:*:*:*:*
cpe:2.3:a:xoops:xoops:2.0.2:*:*:*:*:*:*:*
cpe:2.3:a:xoops:xoops:2.0.3:*:*:*:*:*:*:*
cpe:2.3:a:xoops:xoops:2.0.4:*:*:*:*:*:*:*
cpe:2.3:a:xoops:xoops:2.0.5:*:*:*:*:*:*:*
cpe:2.3:a:xoops:xoops:2.0.5.1:*:*:*:*:*:*:*
cpe:2.3:a:xoops:xoops:2.0.5.2:*:*:*:*:*:*:*
cpe:2.3:a:xoops:xoops:2.0.6:*:*:*:*:*:*:*
cpe:2.3:a:xoops:xoops:2.0.7:*:*:*:*:*:*:*
cpe:2.3:a:xoops:xoops:2.0.9:*:*:*:*:*:*:*
cpe:2.3:a:xoops:xoops:2.0.9.2:*:*:*:*:*:*:*
cpe:2.3:a:xoops:xoops:2.0.9.3:*:*:*:*:*:*:*
cpe:2.3:a:xoops:xoops:2.0.10:*:*:*:*:*:*:*
cpe:2.3:a:xoops:xoops:2.0.11:*:*:*:*:*:*:*
EPSS
Процентиль: 68%
0.00558
Низкий
4.3 Medium
CVSS2
Дефекты
NVD-CWE-Other
Связанные уязвимости
github
почти 4 года назад
Multiple cross-site scripting (XSS) vulnerabilities in XOOPS 2.0.11 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) order parameter to edit.php or (2) cid parameter to comment_edit.php.
EPSS
Процентиль: 68%
0.00558
Низкий
4.3 Medium
CVSS2
Дефекты
NVD-CWE-Other