Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
146377 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.803403
Categoría:Web application abuses
Título:X3 CMS Multiple cross-site scripting (XSS) vulnerabilities
Resumen:x3cms is prone to multiple cross-site scripting vulnerabilities.
Descripción:Summary:
x3cms is prone to multiple cross-site scripting vulnerabilities.

Vulnerability Insight:
- Input passed via the URL to admin/login is not properly sanitised before
being returned to the user.

- Input passed via the 'username' and 'password' POST parameters to
admin/login (when e.g. other POST parameters are not set) is not properly
sanitised before being returned to the user.

Vulnerability Impact:
Successful exploitation will allow remote attackers to execute arbitrary HTML
and script code in a users browser session in context of an affected site and
launch other attacks.

Affected Software/OS:
X3CMS version 0.4.3.1-STABLE and prior

Solution:
Apply the patch from the referenced advisory.

CVSS Score:
4.3

CVSS Vector:
AV:N/AC:M/Au:N/C:N/I:P/A:N

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2011-5255
BugTraq ID: 51346
http://www.securityfocus.com/bid/51346
Bugtraq: 20120111 Multiple Cross-Site-Scripting vulnerabilities in x3cms (Google Search)
http://archives.neohapsis.com/archives/bugtraq/2012-01/0066.html
http://www.infoserve.de/system/files/advisories/INFOSERVE-ADV2011-04.txt
http://osvdb.org/78220
http://secunia.com/advisories/46748
XForce ISS Database: x3cms-login-xss(72279)
https://exchange.xforce.ibmcloud.com/vulnerabilities/72279
CopyrightCopyright (C) 2013 Greenbone AG

Esta es sólo una de 146377 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.