Multiple cross-site scripting (XSS) vulnerabilities in modules_v3/googlemap/wt_v3_street_view.php in webtrees before 1.5.2 allow remote attackers to inject arbitrary web script or HTML via the (1) map, (2) streetview, or (3) reset parameter.
References
Configurations
History
21 Nov 2024, 02:03
Type | Values Removed | Values Added |
---|---|---|
References | () http://secunia.com/advisories/56870 - | |
References | () http://www.rusty-ice.de/advisory/advisory_2014001.txt - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/91133 - |
Information
Published : 2015-01-13 11:59
Updated : 2024-11-21 02:03
NVD link : CVE-2014-100006
Mitre link : CVE-2014-100006
CVE.ORG link : CVE-2014-100006
JSON object : View
Products Affected
webtrees
- webtrees
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')