[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248678

 
 

909

 
 

195426

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2014-2236Date: (C)2014-03-07   (M)2023-12-22


Multiple cross-site scripting (XSS) vulnerabilities in Askbot before 0.7.49 allow remote attackers to inject arbitrary web script or HTML via vectors related to the (1) tag or (2) user search forms.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 4.3
Exploit Score: 8.6
Impact Score: 2.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: MEDIUM
Authentication: NONE
Confidentiality: NONE
Integrity: PARTIAL
Availability: NONE
  
Reference:
SECUNIA-57163
BID-65885
http://www.openwall.com/lists/oss-security/2014/02/28/8
https://bugzilla.redhat.com/show_bug.cgi?id=1070852
https://github.com/ASKBOT/askbot-devel/commit/876e3662ff6b78cc6241338c15e3a0cb49edf4e2#diff-b693b4c02739be4b3231bece15b0eb87
https://github.com/ASKBOT/askbot-devel/commit/a676a86b6b7a5737d4da4f59f71e037406f88d29

CPE    8
cpe:/a:askbot:askbot:0.7.44
cpe:/a:askbot:askbot:0.7.43
cpe:/a:askbot:askbot:0.7.42
cpe:/a:askbot:askbot:0.7.41
...
CWE    1
CWE-79

© SecPod Technologies