![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
CVE ID: | CVE-2011-3979 |
Description: | Cross-site scripting (XSS) vulnerability in ztemp/view_compiled/Theme/theme_admin_setasdefault.php in the theme module in Zikula Application Framework 1.3.0 build 3168, 1.2.7, and probably other versions allows remote attackers to inject arbitrary web script or HTML via the themename parameter in the setasdefault action to index.php. |
Test IDs: | 1.3.6.1.4.1.25623.1.0.103251 |
Cross References: |
Common Vulnerability Exposure (CVE) ID: CVE-2011-3979 BugTraq ID: 49491 http://www.securityfocus.com/bid/49491 Bugtraq: 20110907 XSS in Zikula (Google Search) http://www.securityfocus.com/archive/1/519565/100/0/threaded https://www.htbridge.ch/advisory/xss_in_zikula.html http://osvdb.org/75226 http://secunia.com/advisories/45884 http://securityreason.com/securityalert/8409 XForce ISS Database: zikulaapplication-index-xss(69644) https://exchange.xforce.ibmcloud.com/vulnerabilities/69644 |