Required CVE Record Information
Description
Cross-site scripting (XSS) vulnerability in the Admin portlet in Liferay Portal 4.3.6 allows remote authenticated users to inject arbitrary web script or HTML via the Shutdown message.
References 4 Total
- secunia.com: 28742 third-party-advisory
- kb.cert.org: VU#217825 third-party-advisory
- http://support.liferay.com/browse/LEP-4739
- securityfocus.com: 27554 vdb-entry
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 4 Total
- secunia.com: 28742 third-party-advisoryx_transferred
- kb.cert.org: VU#217825 third-party-advisoryx_transferred
- http://support.liferay.com/browse/LEP-4739 x_transferred
- securityfocus.com: 27554 vdb-entryx_transferred