Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.11449
Category:Web application abuses
Title:eZ Publish Cross Site Scripting Bugs
Summary:eZ Publish 2.2.7 has a cross site scripting bug. An attacker may use it to; perform a cross site scripting attack on this host.;; In addition to this, another flaw may allow an attacker store hostile; HTML code on the server side, which will be executed by the browser of the; administrative user when he looks at the server logs.
Description:Summary:
eZ Publish 2.2.7 has a cross site scripting bug. An attacker may use it to
perform a cross site scripting attack on this host.

In addition to this, another flaw may allow an attacker store hostile
HTML code on the server side, which will be executed by the browser of the
administrative user when he looks at the server logs.

Solution:
Upgrade to a newer version.

CVSS Score:
6.8

CVSS Vector:
AV:N/AC:M/Au:N/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2003-0310
Bugtraq: 20030516 EzPublish Directory XSS Vulnerability (Google Search)
http://marc.info/?l=bugtraq&m=105310013606680&w=2
CopyrightCopyright (C) 2003 k-otik.com

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.