Логотип exploitDog
bind:CVE-2011-3352
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2011-3352

Количество 2

Количество 2

nvd логотип

CVE-2011-3352

около 6 лет назад

Zikula 1.3.0 build #3168 and probably prior has XSS flaw due to improper sanitization of the 'themename' parameter by setting default, modifying and deleting themes. A remote attacker with Zikula administrator privilege could use this flaw to execute arbitrary HTML or web script code in the context of the affected website.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-9px3-cw6w-6qq7

почти 4 года назад

Zikula 1.3.0 build #3168 and probably prior has XSS flaw due to improper sanitization of the 'themename' parameter by setting default, modifying and deleting themes. A remote attacker with Zikula administrator privilege could use this flaw to execute arbitrary HTML or web script code in the context of the affected website.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2011-3352

Zikula 1.3.0 build #3168 and probably prior has XSS flaw due to improper sanitization of the 'themename' parameter by setting default, modifying and deleting themes. A remote attacker with Zikula administrator privilege could use this flaw to execute arbitrary HTML or web script code in the context of the affected website.

CVSS3: 4.8
0%
Низкий
около 6 лет назад
github логотип
GHSA-9px3-cw6w-6qq7

Zikula 1.3.0 build #3168 and probably prior has XSS flaw due to improper sanitization of the 'themename' parameter by setting default, modifying and deleting themes. A remote attacker with Zikula administrator privilege could use this flaw to execute arbitrary HTML or web script code in the context of the affected website.

0%
Низкий
почти 4 года назад

Уязвимостей на страницу