Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2010-1724
Description:Multiple cross-site scripting (XSS) vulnerabilities in Zikula Application Framework 1.2.2, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) func parameter to index.php, or the (2) lang parameter to index.php, which is not properly handled by ZLanguage.php.
Test IDs: 1.3.6.1.4.1.25623.1.0.67529   1.3.6.1.4.1.25623.1.0.67528  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2010-1724
BugTraq ID: 39717
http://www.securityfocus.com/bid/39717
Bugtraq: 20100427 XSS vulnerability in Zikula Application Framework (Google Search)
http://www.securityfocus.com/archive/1/510988/100/0/threaded
http://www.htbridge.ch/advisory/xss_vulnerability_in_zikula_application_framework.html
http://www.htbridge.ch/advisory/xss_vulnerability_in_zikula_application_framework_1.html
http://www.osvdb.org/64095
http://osvdb.org/64096
http://secunia.com/advisories/39614
XForce ISS Database: zikula-index-xss(58224)
https://exchange.xforce.ibmcloud.com/vulnerabilities/58224




© 1998-2025 E-Soft Inc. All rights reserved.