Multiple cross-site scripting (XSS) vulnerabilities in the IVYWE (1) Assist plugin before 1.1.2.test20160906, (2) dataBox plugin before 0.0.0.20160906, and (3) userBox plugin before 0.0.0.20160906 for Geeklog allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
References
Link | Resource |
---|---|
http://jvn.jp/en/jp/JVN46087986/index.html | Third Party Advisory VDB Entry |
http://jvndb.jvn.jp/en/contents/2016/JVNDB-2016-000167.html | Third Party Advisory VDB Entry |
http://www.securityfocus.com/bid/93123 | Third Party Advisory VDB Entry |
https://github.com/ivywe/geeklog-ivywe/commit/3cdb4ebca5746ff1e02b7e434d5722044d1d09d1 | Patch Third Party Advisory |
https://github.com/ivywe/geeklog-ivywe/commit/fe20a1bccdfec96125ab3d8dbee6ccbd0767c0be | Patch Third Party Advisory |
http://jvn.jp/en/jp/JVN46087986/index.html | Third Party Advisory VDB Entry |
http://jvndb.jvn.jp/en/contents/2016/JVNDB-2016-000167.html | Third Party Advisory VDB Entry |
http://www.securityfocus.com/bid/93123 | Third Party Advisory VDB Entry |
https://github.com/ivywe/geeklog-ivywe/commit/3cdb4ebca5746ff1e02b7e434d5722044d1d09d1 | Patch Third Party Advisory |
https://github.com/ivywe/geeklog-ivywe/commit/fe20a1bccdfec96125ab3d8dbee6ccbd0767c0be | Patch Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 02:53
Type | Values Removed | Values Added |
---|---|---|
References | () http://jvn.jp/en/jp/JVN46087986/index.html - Third Party Advisory, VDB Entry | |
References | () http://jvndb.jvn.jp/en/contents/2016/JVNDB-2016-000167.html - Third Party Advisory, VDB Entry | |
References | () http://www.securityfocus.com/bid/93123 - Third Party Advisory, VDB Entry | |
References | () https://github.com/ivywe/geeklog-ivywe/commit/3cdb4ebca5746ff1e02b7e434d5722044d1d09d1 - Patch, Third Party Advisory | |
References | () https://github.com/ivywe/geeklog-ivywe/commit/fe20a1bccdfec96125ab3d8dbee6ccbd0767c0be - Patch, Third Party Advisory |
Information
Published : 2017-04-14 18:59
Updated : 2024-11-21 02:53
NVD link : CVE-2016-4875
Mitre link : CVE-2016-4875
CVE.ORG link : CVE-2016-4875
JSON object : View
Products Affected
databox_project
- databox_plugin
assist_project
- assist_plugin
userbox_project
- userbox_plugin
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')