Описание
Multiple cross-site scripting (XSS) vulnerabilities in index.php in Aardvark Topsites PHP 5.2.0 and 5.2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) mail, (2) title, (3) u, and (4) url parameters. NOTE: the q parameter is already covered by CVE-2009-2302.
Ссылки
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:a:avatic:aardvark_topsites_php:5.2.0:*:*:*:*:*:*:*
cpe:2.3:a:avatic:aardvark_topsites_php:5.2.1:*:*:*:*:*:*:*
EPSS
Процентиль: 49%
0.00254
Низкий
4.3 Medium
CVSS2
Дефекты
CWE-79
Связанные уязвимости
github
больше 3 лет назад
Multiple cross-site scripting (XSS) vulnerabilities in index.php in Aardvark Topsites PHP 5.2.0 and 5.2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) mail, (2) title, (3) u, and (4) url parameters. NOTE: the q parameter is already covered by CVE-2009-2302.
EPSS
Процентиль: 49%
0.00254
Низкий
4.3 Medium
CVSS2
Дефекты
CWE-79