Required CVE Record Information
Description
Cross-site scripting (XSS) vulnerability in admin/managerrelated.php in the administrative backend in Absolut Engine 1.73 allows remote authenticated users to inject arbitrary web script or HTML via the title parameter.
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 3 Total
- http://sroesemann.blogspot.de/2014/12/sroeadv-2014-08.html x_transferred
- seclists.org: 20141230 Multiple SQL Injections and Reflecting XSS in Absolut Engine v. 1.73 CMS mailing-listx_transferred
- securityfocus.com: 71822 vdb-entryx_transferred