Page 7 of 32 results (0.048 seconds)

CVSS: 4.3EPSS: 0%CPEs: 9EXPL: 1

Multiple cross-site scripting (XSS) vulnerabilities in dotCMS before 2.3.2 allow remote attackers to inject arbitrary web script or HTML via the (1) _loginUserName parameter to application/login/login.html, (2) my_account_login parameter to c/portal_public/login, or (3) email parameter to forgotPassword. Múltiples vulnerabilidades de XSS en dotCMS anterior a 2.3.2 permiten a atacantes remotos inyectar script Web o HTML arbitrarios a través del (1) parámetro _loginUserName hacia application/login/login.html, (2) parámetro my_account_login hacia c/portal_public/login o (3) parámetro email hacia forgotPassword. • http://dotcms.com/security/SI-14 http://secunia.com/advisories/53265 https://github.com/dotCMS/dotCMS/issues/2949 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 4.3EPSS: 0%CPEs: 13EXPL: 0

Cross-site scripting (XSS) vulnerability in search-results.dot in dotCMS 1.x allows remote attackers to inject arbitrary web script or HTML via the search_query parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. Vulnerabilidad de secuencias de comandos en sitios cruzados en search-results.dot de dotCMS, permite a atacantes remotos, inyectar secuencias de comandos web o HTML a través del parámetro search_query. NOTA: el origen de esta información es desconocido; los detalles se han obtenido únicamente de información de terceros. • http://secunia.com/advisories/30307 http://www.securityfocus.com/bid/29287 https://exchange.xforce.ibmcloud.com/vulnerabilities/42525 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •