CVE-2013-1780
https://notcve.org/view.php?id=CVE-2013-1780
Cross-site scripting (XSS) vulnerability in the Best Responsive Theme 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users with the administer themes permission to inject arbitrary web script or HTML via vectors related to social icons. Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en el tema Best Responsive v7.x-1.x anterior a v7.x-1.4 para Drupal permite a usuarios remotos autenticados con permisos para administrar temas inyectar secuencias de comandos web o HTML a través de vectores relacionados con los iconos sociales. • http://drupal.org/node/1929390 http://drupal.org/node/1929484 http://drupalcode.org/project/best_responsive.git/commitdiff/5972126 http://osvdb.org/90690 http://secunia.com/advisories/52421 http://www.openwall.com/lists/oss-security/2013/02/28/3 http://www.securityfocus.com/bid/58213 https://exchange.xforce.ibmcloud.com/vulnerabilities/82469 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •