Multiple cross-site scripting (XSS) vulnerabilities in the sed_import function in system/functions.php in Neocrome Seditio build 160 and 161 allow remote attackers to inject arbitrary web script or HTML via the (1) newmsg or (2) rtext parameter. NOTE: some of these details are obtained from third party information.
References
Configurations
History
21 Nov 2024, 01:45
Type | Values Removed | Values Added |
---|---|---|
References | () http://osvdb.org/80688 - | |
References | () http://packetstormsecurity.org/files/111320/Seditio-Build-161-Cross-Site-Scripting-Information-Disclosure.html - Exploit | |
References | () http://secunia.com/advisories/48637 - | |
References | () http://www.neocrome.net/page.php?id=2470 - | |
References | () http://www.securityfocus.com/bid/52802 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/74463 - |
Information
Published : 2012-11-17 21:55
Updated : 2025-04-11 00:51
NVD link : CVE-2012-5914
Mitre link : CVE-2012-5914
CVE.ORG link : CVE-2012-5914
JSON object : View
Products Affected
neocrome
- seditio
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')