cross-site scripting (XSS) in compat.php in Serendipity prima 0.7.1 consente agli aggressori remoti di inserire lo script Web arbitrario o HTML tramite la variabile searchTerm. |
http://www.securityfocus.com/bid/11790 http://sourceforge.net/tracker/index.php?func=detail&aid=1076762&group_id=75065&atid=542822 http://www.osvdb.org/12177 http://securitytracker.com/id?1012383 http://secunia.com/advisories/13357 https://exchange.xforce.ibmcloud.com/vulnerabilities/18322 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-2525 |
Vulnerabilità: CVE-2004-2525
