Описание
Multiple cross-site scripting (XSS) vulnerabilities in eXtplorer 2.1.3, when used as a component for Joomla!, allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) application.js.php in scripts/ or (2) admin.php, (3) copy_move.php, (4) functions.php, (5) header.php, or (6) upload.php in include/.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | DNE | |
| esm-apps/xenial | not-affected | 2.1.0b6+dfsg.3-4+deb7u1 |
| esm-infra-legacy/trusty | DNE | trusty/esm was DNE [trusty was released [2.1.0b6+dfsg.3-4+deb7u1~build0.14.04.1]] |
| lucid | DNE | |
| precise | ignored | end of life |
| precise/esm | DNE | precise was needed |
| quantal | ignored | end of life |
| saucy | ignored | end of life |
| trusty | released | 2.1.0b6+dfsg.3-4+deb7u1~build0.14.04.1 |
| trusty/esm | DNE | trusty was released [2.1.0b6+dfsg.3-4+deb7u1~build0.14.04.1] |
Показывать по
EPSS
2.6 Low
CVSS2
Связанные уязвимости
Multiple cross-site scripting (XSS) vulnerabilities in eXtplorer 2.1.3, when used as a component for Joomla!, allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) application.js.php in scripts/ or (2) admin.php, (3) copy_move.php, (4) functions.php, (5) header.php, or (6) upload.php in include/.
Multiple cross-site scripting (XSS) vulnerabilities in eXtplorer 2.1.3 ...
Multiple cross-site scripting (XSS) vulnerabilities in eXtplorer 2.1.3, when used as a component for Joomla!, allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) application.js.php in scripts/ or (2) admin.php, (3) copy_move.php, (4) functions.php, (5) header.php, or (6) upload.php in include/.
EPSS
2.6 Low
CVSS2