CVE-2013-7194
N/A
N/A
Summary
Multiple cross-site scripting (XSS) vulnerabilities in www/administrator.php in eFront 3.6.14 (build 18012) allow remote authenticated administrators to inject arbitrary web script or HTML via the (1) Last name, (2) Lesson name, or (3) Course name field.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
ADP Enrichment
CVE Program Container
Additional References
- http://www.exploit-db.com/exploits/30213
- http://packetstormsecurity.com/files/124400
- https://exchange.xforce.ibmcloud.com/vulnerabilities/89660
References
- http://www.exploit-db.com/exploits/30213
- http://packetstormsecurity.com/files/124400
- https://exchange.xforce.ibmcloud.com/vulnerabilities/89660
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.