[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248678

 
 

909

 
 

195426

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2013-7241Date: (C)2014-01-03   (M)2024-02-22


Cross-site scripting (XSS) vulnerability in the export function in zp-core/zp-extensions/mergedRSS.php in Zenphoto before 1.4.5.4 allows remote attackers to inject arbitrary web script or HTML via the URI.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 4.3
Exploit Score: 8.6
Impact Score: 2.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: MEDIUM
Authentication: NONE
Confidentiality: NONE
Integrity: PARTIAL
Availability: NONE
  
Reference:
http://seclists.org/bugtraq/2013/Oct/20
BID-62815
http://openwall.com/lists/oss-security/2013/12/29/1
http://openwall.com/lists/oss-security/2013/12/30/10
http://www.enkomio.com/Advisory/SOJOBO-ADV-13-01
http://www.zenphoto.org/news/zenphoto-1.4.5.4

CWE    1
CWE-79

© SecPod Technologies