CVE-2010-1482
N/A
N/A
Summary
Cross-site scripting (XSS) vulnerability in admin/editprefs.php in the backend in CMS Made Simple (CMSMS) before 1.7.1 might allow remote attackers to inject arbitrary web script or HTML via the date_format_string parameter.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
ADP Enrichment
CVE Program Container
Additional References
- http://blog.cmsmadesimple.org/2010/05/01/announcing-cms-made-simple-1-7-1-escade/
- http://www.securityfocus.com/bid/39997
- http://int21.de/cve/CVE-2010-1482-cmsmadesimple-xss-backend.html
- http://www.securityfocus.com/archive/1/511178
References
- http://blog.cmsmadesimple.org/2010/05/01/announcing-cms-made-simple-1-7-1-escade/
- http://www.securityfocus.com/bid/39997
- http://int21.de/cve/CVE-2010-1482-cmsmadesimple-xss-backend.html
- http://www.securityfocus.com/archive/1/511178
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.