CVE-2011-3979

Cross-site scripting (XSS) vulnerability in ztemp/view_compiled/Theme/theme_admin_setasdefault.php in the theme module in Zikula Application Framework 1.3.0 build 3168, 1.2.7, and probably other versions allows remote attackers to inject arbitrary web script or HTML via the themename parameter in the setasdefault action to index.php.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:zikula:zikula_application_framework:1.2.7:*:*:*:*:*:*:*
cpe:2.3:a:zikula:zikula_application_framework:1.3.0:*:*:*:*:*:*:*

Information

Published : 2011-10-04 03:55

Updated : 2018-10-09 12:33


NVD link : CVE-2011-3979

Mitre link : CVE-2011-3979


JSON object : View

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Advertisement

dedicated server usa

Products Affected

zikula

  • zikula_application_framework