CVE Database
/

CVE-2011-4572

Back to search

CVE-2011-4572

Published: Nov 29, 2011

Modified: Aug 7, 2024

PUBLISHED

Description

Cross-site scripting (XSS) vulnerability in inc/tesmodrewite.php in CF Image Hosting Script 1.3.82, 1.4.1, and probably other versions before 1.4.2 allows remote attackers to inject arbitrary web script or HTML via the q parameter. NOTE: this was originally reported as a file disclosure vulnerability, but this is likely inaccurate.

VendorProductVersions

n/a

n/a

affected
n/a

References

17927
exploit
x_refsource_EXPLOIT-DB
46290
third-party-advisory
x_refsource_SECUNIA
76059
vdb-entry
x_refsource_OSVDB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now