CVE-2013-1466

Multiple cross-site scripting (XSS) vulnerabilities in glFusion before 1.2.2.pl4 allow remote attackers to inject arbitrary web script or HTML via the (1) subject parameter to profiles.php; (2) address1, (3) address2, (4) calendar_type, (5) city, (6) state, (7) title, (8) url, or (9) zipcode parameter to calendar/index.php; (10) title or (11) url parameter to links/index.php; or (12) PATH_INFO to admin/plugins/mediagallery/xppubwiz.php/.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 93%
VendorProductVersion
glfusionglfusion
𝑥
≤ 1.2.2.pl3
glfusionglfusion
1.0.0
glfusionglfusion
1.0.0:rc1
glfusionglfusion
1.0.0:rc2
glfusionglfusion
1.0.1
glfusionglfusion
1.0.2
glfusionglfusion
1.1.0
glfusionglfusion
1.1.0:rc1
glfusionglfusion
1.1.1
glfusionglfusion
1.1.2
glfusionglfusion
1.1.3
glfusionglfusion
1.1.4
glfusionglfusion
1.1.4.pl1:pl1
glfusionglfusion
1.1.4.pl2:pl2
glfusionglfusion
1.1.4.pl3:pl3
glfusionglfusion
1.1.4.pl4:pl4
glfusionglfusion
1.1.5
glfusionglfusion
1.1.5.pl1:pl1
glfusionglfusion
1.1.5.pl2:pl2
glfusionglfusion
1.1.5.pl3:pl3
glfusionglfusion
1.1.6
glfusionglfusion
1.1.6.pl1:pl1
glfusionglfusion
1.1.6.pl2:pl2
glfusionglfusion
1.1.6.pl3:pl3
glfusionglfusion
1.1.6.pl4:pl4
glfusionglfusion
1.1.7
glfusionglfusion
1.1.8
glfusionglfusion
1.1.8.pl1:pl1
glfusionglfusion
1.1.8.pl2:pl2
glfusionglfusion
1.1.8.pl3:pl3
glfusionglfusion
1.1.8.pl4:pl4
glfusionglfusion
1.1.8.pl5:pl5
glfusionglfusion
1.1.8.pl6:pl6
glfusionglfusion
1.2.0
glfusionglfusion
1.2.0.pl1:pl1
glfusionglfusion
1.2.0.pl2:pl2
glfusionglfusion
1.2.0.pl3:pl3
glfusionglfusion
1.2.0.pl4:pl4
glfusionglfusion
1.2.0.pl5:pl5
glfusionglfusion
1.2.0.pl6:pl6
glfusionglfusion
1.2.0.pl7:pl7
glfusionglfusion
1.2.2
glfusionglfusion
1.2.2.pl1:pl1
glfusionglfusion
1.2.2.pl2:pl2
𝑥
= Vulnerable software versions