CVE-2011-1953
06.06.2011, 19:55
Multiple cross-site scripting (XSS) vulnerabilities in common.php in Post Revolution before 0.8.0c-2 allow remote attackers to inject arbitrary web script or HTML via an attribute of a (1) P, a (2) STRONG, a (3) A, a (4) EM, a (5) I, a (6) IMG, a (7) LI, an (8) OL, a (9) VIDEO, or a (10) BLOCKQUOTE element.
Vendor | Product | Version |
---|---|---|
postrev | post_revolution | 𝑥 ≤ 0.8.0c |
postrev | post_revolution | 0.6.2:beta |
postrev | post_revolution | 0.6.3:beta |
postrev | post_revolution | 0.6.4 |
postrev | post_revolution | 0.6.5 |
postrev | post_revolution | 0.6.6 |
postrev | post_revolution | 0.7.0:rc1 |
postrev | post_revolution | 0.7.0:rc2 |
postrev | post_revolution | 0.7.0:rc3 |
postrev | post_revolution | 0.7.0:rc4 |
postrev | post_revolution | 0.8.0:alpha |
postrev | post_revolution | 0.8.0b:b |
𝑥
= Vulnerable software versions
References