Описание
Multiple cross-site scripting (XSS) vulnerabilities pm_popup.php in MKPortal 1.1 Rc1 and earlier, as used with vBulletin 3.5.4 and earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) u1, (2) m1, (3) m2, (4) m3, (5) m4 parameters.
Ссылки
- Vendor Advisory
- Exploit
- ExploitVendor Advisory
- Vendor Advisory
- Vendor Advisory
- Exploit
- ExploitVendor Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:mkportal:mkportal:1.1_rc1:*:*:*:*:*:*:*
EPSS
Процентиль: 93%
0.09706
Низкий
4.3 Medium
CVSS2
Дефекты
CWE-79
Связанные уязвимости
github
почти 4 года назад
Multiple cross-site scripting (XSS) vulnerabilities pm_popup.php in MKPortal 1.1 Rc1 and earlier, as used with vBulletin 3.5.4 and earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) u1, (2) m1, (3) m2, (4) m3, (5) m4 parameters.
EPSS
Процентиль: 93%
0.09706
Низкий
4.3 Medium
CVSS2
Дефекты
CWE-79