CVE-2013-6047

Multiple cross-site scripting (XSS) vulnerabilities in the site creation interface in ikiwiki-hosting before 0.20131025 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ikiwiki_hosting_project:ikiwiki_hosting:*:*:*:*:*:*:*:*
cpe:2.3:a:ikiwiki_hosting_project:ikiwiki_hosting:0.20110401:*:*:*:*:*:*:*
cpe:2.3:a:ikiwiki_hosting_project:ikiwiki_hosting:0.20110420:*:*:*:*:*:*:*
cpe:2.3:a:ikiwiki_hosting_project:ikiwiki_hosting:0.20110424:*:*:*:*:*:*:*
cpe:2.3:a:ikiwiki_hosting_project:ikiwiki_hosting:0.20110515:*:*:*:*:*:*:*
cpe:2.3:a:ikiwiki_hosting_project:ikiwiki_hosting:0.20110608:*:*:*:*:*:*:*
cpe:2.3:a:ikiwiki_hosting_project:ikiwiki_hosting:0.20110926:*:*:*:*:*:*:*
cpe:2.3:a:ikiwiki_hosting_project:ikiwiki_hosting:0.20111005:*:*:*:*:*:*:*
cpe:2.3:a:ikiwiki_hosting_project:ikiwiki_hosting:0.20120125:*:*:*:*:*:*:*
cpe:2.3:a:ikiwiki_hosting_project:ikiwiki_hosting:0.20120131:*:*:*:*:*:*:*
cpe:2.3:a:ikiwiki_hosting_project:ikiwiki_hosting:0.20120425:*:*:*:*:*:*:*
cpe:2.3:a:ikiwiki_hosting_project:ikiwiki_hosting:0.20120526:*:*:*:*:*:*:*
cpe:2.3:a:ikiwiki_hosting_project:ikiwiki_hosting:0.20120527:*:*:*:*:*:*:*
cpe:2.3:a:ikiwiki_hosting_project:ikiwiki_hosting:0.20130504:*:*:*:*:*:*:*

History

21 Nov 2024, 01:58

Type Values Removed Values Added
References () http://osvdb.org/99012 - () http://osvdb.org/99012 -
References () http://packages.qa.debian.org/i/ikiwiki-hosting/news/20131025T224825Z.html - () http://packages.qa.debian.org/i/ikiwiki-hosting/news/20131025T224825Z.html -
References () http://seclists.org/oss-sec/2013/q4/180 - () http://seclists.org/oss-sec/2013/q4/180 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/88334 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/88334 -

Information

Published : 2014-02-25 15:55

Updated : 2025-04-11 00:51


NVD link : CVE-2013-6047

Mitre link : CVE-2013-6047

CVE.ORG link : CVE-2013-6047


JSON object : View

Products Affected

ikiwiki_hosting_project

  • ikiwiki_hosting
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')