CVE-2014-4853
10.07.2014, 16:55
Cross-site scripting (XSS) vulnerability in odm-init.php in OpenDocMan before 1.2.7.3 allows remote authenticated users to inject arbitrary web script or HTML via the file name of an uploaded file.
| Vendor | Product | Version |
|---|---|---|
| opendocman | opendocman | 𝑥 ≤ 1.2.7.2 |
| opendocman | opendocman | 1.2.6.2 |
| opendocman | opendocman | 1.2.6.2:a |
| opendocman | opendocman | 1.2.6.2:b |
| opendocman | opendocman | 1.2.6.3 |
| opendocman | opendocman | 1.2.6.3:a |
| opendocman | opendocman | 1.2.6.5 |
| opendocman | opendocman | 1.2.6.6 |
| opendocman | opendocman | 1.2.6.7 |
| opendocman | opendocman | 1.2.6.7:beta |
| opendocman | opendocman | 1.2.6.8 |
| opendocman | opendocman | 1.2.7 |
| opendocman | opendocman | 1.2.7.1 |
𝑥
= Vulnerable software versions
References