CVE Database
/

CVE-2015-1058

Back to search

CVE-2015-1058

Published: Jan 16, 2015

Modified: Aug 6, 2024

PUBLISHED

Description

Multiple cross-site scripting (XSS) vulnerabilities in AdaptCMS 3.0.3 allow remote attackers to inject arbitrary web script or HTML via the (1) data[Category][title] parameter to admin/categories/add, (2) data[Field][title] parameter to admin/fields/ajax_fields/, (3) name property in a basicInfo JSON object to admin/tools/create_theme, (4) data[Link][link_title] parameter to admin/links/links/add, or (5) data[ForumTopic][subject] parameter to forums/off-topic/new.

VendorProductVersions

n/a

n/a

affected
n/a

References

116718
vdb-entry
x_refsource_OSVDB
116719
vdb-entry
x_refsource_OSVDB
adaptcms-multiple-data-xss(99617)
vdb-entry
x_refsource_XF
116716
vdb-entry
x_refsource_OSVDB
116720
vdb-entry
x_refsource_OSVDB
116717
vdb-entry
x_refsource_OSVDB
35710
exploit
x_refsource_EXPLOIT-DB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now