CVE-2011-4918
Multiple cross-site scripting (XSS) vulnerabilities in Elxis CMS 2009.2, 2009.3 and 2009.3 Aphrodite before revision 2684 allow remote attackers to inject arbitrary web script or HTML via the (1) task parameter to elxis/index.php, and (2) PATH_INFO to…
Does this matter?
Lower severity and a low EPSS score (2.11%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple cross-site scripting (XSS) vulnerabilities in Elxis CMS 2009.2, 2009.3 and 2009.3 Aphrodite before revision 2684 allow remote attackers to inject arbitrary web script or HTML via the (1) task parameter to elxis/index.php, and (2) PATH_INFO to elxis/administrator/index.php.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 2.11% probability · 81th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- elxis/elxis cms
- Source
- secalert@redhat.com
References
- http://forum.elxis.org/index.php?PHPSESSID=v9i7kgmmb2554ldmlcmbj32ugjd0ngpc&topic=5144.msg43327#msg43327Patch
- http://secunia.com/advisories/47073Vendor Advisory
- http://www.openwall.com/lists/oss-security/2011/12/31/2
- http://www.osvdb.org/77563Exploit
- http://www.osvdb.org/77564Exploit
- http://www.securityfocus.com/archive/1/520748/100/0/threaded
- http://www.securityfocus.com/bid/50910Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/71648
- http://forum.elxis.org/index.php?PHPSESSID=v9i7kgmmb2554ldmlcmbj32ugjd0ngpc&topic=5144.msg43327#msg43327Patch
- http://secunia.com/advisories/47073Vendor Advisory
- http://www.openwall.com/lists/oss-security/2011/12/31/2
- http://www.osvdb.org/77563Exploit
- http://www.osvdb.org/77564Exploit
- http://www.securityfocus.com/archive/1/520748/100/0/threaded
- http://www.securityfocus.com/bid/50910Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/71648
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.