Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2015-5456
Description:Cross-site scripting (XSS) vulnerability in the form method in modules/formclass.php in PivotX before 2.3.11 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO, related to the "PHP_SELF" variable and form actions.
Test IDs: None available
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2015-5456
BugTraq ID: 75577
http://www.securityfocus.com/bid/75577
Bugtraq: 20150627 Session Fixation, Reflected XSS, Code Execution in PivotX 2.3.10 (Google Search)
http://www.securityfocus.com/archive/1/535860/100/0/threaded
http://packetstormsecurity.com/files/132474/PivotX-2.3.10-Session-Fixation-XSS-Code-Execution.html
http://software-talk.org/blog/2015/06/session-fixation-xss-code-execution-vulnerability-pivotx/




© 1998-2025 E-Soft Inc. All rights reserved.