CVE-2013-1407 – Events Manager < 5.3.5 & Events Manager Pro < 2.2.9 - Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2013-1407
Multiple cross-site scripting (XSS) vulnerabilities in the Events Manager plugin before 5.3.5 and Events Manager Pro plugin before 2.2.9 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) scope parameter to index.php; (2) user_name, (3) dbem_phone, (4) user_email, or (5) booking_comment parameter to an event with registration enabled; or the (6) _wpnonce parameter to wp-admin/edit.php. Múltiples vulnerabilidades de tipo cross-site-scripting (XSS) en el plugin Events Manager anterior a versión 5.3.5 y el plugin Events Manager Pro anterior a versión 2.2.9 para WordPress, permiten a los atacantes remotos inyectar script web o HTML arbitrario por medio del parámetro (1) scope en el archivo index.php; del parámetro (2) user_name, (3) dbem_phone, (4) user_email o (5) booking_comment a un evento con el registro habilitado; o el parámetro (6) _wpnonce en el archivo wp-admin/edit.php. WordPress Events Manager plugin version 5.3.3 suffers from a cross site scripting vulnerability. • http://archives.neohapsis.com/archives/bugtraq/2013-03/0034.html http://wp-events-plugin.com/blog/2013/01/22/5-3-5-released-includes-a-security-update https://www.htbridge.com/advisory/HTB23139 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2013-7480 – Events Manager <= 5.3.6 - Multiple Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2013-7480
The events-manager plugin before 5.3.6.1 for WordPress has XSS via the booking form and admin areas. El plugin events-manager versiones anteriores a 5.3.6.1 para WordPress, presenta una vulnerabilidad de tipo XSS por medio del formulario de reserva y las áreas de administración. • https://wordpress.org/plugins/events-manager/#developers • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •