CVE-2014-9433

EUVD-2014-9254
Multiple cross-site scripting (XSS) vulnerabilities in cms/front_content.php in Contenido before 4.9.6, when advanced mod rewrite (AMR) is disabled, allow remote attackers to inject arbitrary web script or HTML via the (1) idart, (2) lang, or (3) idcat parameter.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
2.6 UNKNOWN
NETWORK
HIGH
AV:N/AC:H/Au:N/C:N/I:P/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 61%
Affected Products (NVD)
VendorProductVersion
contenidocontendio
4.9.0
contenidocontendio
4.9.1
contenidocontendio
4.9.2
contenidocontendio
4.9.3
contenidocontendio
4.9.4
contenidocontendio
4.9.5
𝑥
= Vulnerable software versions