CVE Database
/

CVE-2013-3535

Back to search

CVE-2013-3535

Published: May 13, 2013

Modified: Aug 6, 2024

PUBLISHED

Description

Multiple cross-site scripting (XSS) vulnerabilities in CMSLogik 1.2.0 and 1.2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) admin_email, (2) header_title, (3) site_title parameter to admin/settings; (4) recaptcha_private or (5) recaptcha_public parameter to admin/captcha_settings; (6) fb_appid, (7) fp_secret, (8) tw_consumer_key, or (9) tw_consumer_secret parameter to admin/social_settings; (10) slug parameter to admin/gallery/save_item_settings; or (11) item_link parameter to admin/edit_menu_item_ajax. NOTE: this issue might be resultant from CSRF.

VendorProductVersions

n/a

n/a

affected
n/a

References

24959
exploit
x_refsource_EXPLOIT-DB
cmslogik-multiple-xss(83429)
vdb-entry
x_refsource_XF
92326
vdb-entry
x_refsource_OSVDB
92323
vdb-entry
x_refsource_OSVDB
92324
vdb-entry
x_refsource_OSVDB
92322
vdb-entry
x_refsource_OSVDB
92325
vdb-entry
x_refsource_OSVDB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now