CVE-2010-2671
08.07.2010, 22:30
Cross-site scripting (XSS) vulnerability in advancedsearch.php in eZ Publish 3.7.0 through 4.2.0 allows remote attackers to inject arbitrary web script or HTML via the subTreeItem parameter.
Vendor | Product | Version |
---|---|---|
ez | ez_publish | 3.7.0 |
ez | ez_publish | 3.7.1 |
ez | ez_publish | 3.7.2 |
ez | ez_publish | 3.7.3 |
ez | ez_publish | 3.7.4 |
ez | ez_publish | 3.7.5 |
ez | ez_publish | 3.7.6 |
ez | ez_publish | 3.7.7 |
ez | ez_publish | 3.7.8 |
ez | ez_publish | 3.7.9 |
ez | ez_publish | 3.7.10 |
ez | ez_publish | 3.7.11 |
ez | ez_publish | 3.7.12 |
ez | ez_publish | 4.2.0 |
𝑥
= Vulnerable software versions
References