|
|
| |
| CMSMini is affected by XSS vulnerabilities in version 0.2.2. |
| |
Credit:
The original article can be found at: http://www.mavitunasecurity.com/xss-vulnerabilities-in-cmsmini/
The information has been provided by Canberk Bolat.
|
| |
Vulnerable Systems:
* CMSMini 0.2.2
http://example.com/view/index.php?path='%22--%3E%3C/style%3E%3C/script%3E%3Cscript%3Ealert(0x0000A3)%3C/script%3E&p=cms.guestbook&msg=Message%20sent
Vendor Status:
Currently we are not aware of any updates from the vendor.
Disclosure Timeline:
23/01/2011 - No contact info
19/10/2012 - Advisory released
|
|
blog comments powered by
|