CVE-2012-0986
06.10.2012, 21:55
Multiple cross-site scripting (XSS) vulnerabilities in ImpressCMS 1.2.x before 1.2.7 Final and 1.3.x before 1.3.1 Final allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) notifications.php, (2) modules/system/admin/images/browser.php, and (3) modules/content/admin/content.php.
Vendor | Product | Version |
---|---|---|
impresscms | impresscms | 1.2:alpha1 |
impresscms | impresscms | 1.2:alpha2 |
impresscms | impresscms | 1.2:beta |
impresscms | impresscms | 1.2:final |
impresscms | impresscms | 1.2:rc1 |
impresscms | impresscms | 1.2:rc2 |
impresscms | impresscms | 1.2.1:beta |
impresscms | impresscms | 1.2.1:final |
impresscms | impresscms | 1.2.1:rc1 |
impresscms | impresscms | 1.2.3:beta |
impresscms | impresscms | 1.2.3:final |
impresscms | impresscms | 1.2.3:rc1 |
impresscms | impresscms | 1.2.3:rc2 |
impresscms | impresscms | 1.2.4:final |
impresscms | impresscms | 1.2.5:final |
impresscms | impresscms | 1.2.6:final |
impresscms | impresscms | 1.3 |
𝑥
= Vulnerable software versions
References