Required CVE Record Information
Description
Multiple cross-site scripting (XSS) vulnerabilities in OpenX Source 2.8.10 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) package parameter to www/admin/plugin-index.php or the (2) group parameter to www/admin/plugin-settings.php.
References 9 Total
- https://svn.openx.org/openx/trunk/www/admin/plugin-settings.php
- https://svn.openx.org/openx/trunk/www/admin/plugin-index.php
- https://www.htbridge.com/advisory/HTB23155-openx-changeset-82710.diff
- exchange.xforce.ibmcloud.com: openx-cve20133515-multiple-xss(85411) vdb-entry
- osvdb.org: 94774 vdb-entry
- seclists.org: 20130703 Multiple Vulnerabilities in OpenX mailing-list
- https://www.htbridge.com/advisory/HTB23155
- exploit-db.com: 26624 exploit
- osvdb.org: 94775 vdb-entry
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 9 Total
- https://svn.openx.org/openx/trunk/www/admin/plugin-settings.php x_transferred
- https://svn.openx.org/openx/trunk/www/admin/plugin-index.php x_transferred
- https://www.htbridge.com/advisory/HTB23155-openx-changeset-82710.diff x_transferred
- exchange.xforce.ibmcloud.com: openx-cve20133515-multiple-xss(85411) vdb-entryx_transferred
- osvdb.org: 94774 vdb-entryx_transferred
- seclists.org: 20130703 Multiple Vulnerabilities in OpenX mailing-listx_transferred
- https://www.htbridge.com/advisory/HTB23155 x_transferred
- exploit-db.com: 26624 exploitx_transferred
- osvdb.org: 94775 vdb-entryx_transferred