1 results (0.009 seconds)

CVSS: 4.3EPSS: 0%CPEs: 4EXPL: 2

Cross-site scripting (XSS) vulnerability in controlpanel/loading.aspx in Telligent Evolution before 6.1.19.36103, 7.x before 7.1.12.36162, 7.5.x, and 7.6.x before 7.6.7.36651 allows remote attackers to inject arbitrary web script or HTML via the msg parameter. NOTE: some of these details are obtained from third party information. Vulnerabilidad de XSS en controlpanel/loading.aspx en Telligent Evolution anterior a 6.1.19.36103, 7.x anterior a 7.1.12.36162, 7.5.x y 7.6.x anterior a 7.6.7.36651 permite a atacantes remotos inyectar script Web o HTML arbitrarios a través del parámetro msg. NOTA: algunos de estos datos se obtienen de información de terceros. Telligent Evolution version 7.5.0.32466 suffers from a cross site scripting vulnerability. • http://secunia.com/advisories/56779 http://www.securityfocus.com/archive/1/531223/100/0/threaded http://www.securityfocus.com/bid/65739 https://www.portcullis-security.com/security-research-and-downloads/security-advisories/cve-2014-1223 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •