CVE-2014-4763
https://notcve.org/view.php?id=CVE-2014-4763
Cross-site scripting (XSS) vulnerability in Content Navigator in Content Engine in IBM FileNet Content Manager 5.2.x before 5.2.0.3-P8CPE-IF003 and Content Foundation 5.2.x before 5.2.0.3-P8CPE-IF003 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL. Vulnerabilidad de XSS en Content Navigator en Content Engine en IBM FileNet Content Manager 5.2.x anterior a 5.2.0.3-P8CPE-IF003 y Content Foundation 5.2.x anterior a 5.2.0.3-P8CPE-IF003 permite a usuarios remotos autenticados inyectar secuencias de comandos web o HTML arbitrarios a través de una URL manipulada. • http://secunia.com/advisories/61127 http://www-01.ibm.com/support/docview.wss?uid=swg21679930 http://www-01.ibm.com/support/docview.wss?uid=swg21685574 http://www.securityfocus.com/bid/69798 https://exchange.xforce.ibmcloud.com/vulnerabilities/94660 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2013-6746
https://notcve.org/view.php?id=CVE-2013-6746
Cross-site scripting (XSS) vulnerability in FileNet P8 Platform Documentation Installable Info Center 4.5.1 through 5.2.0 in IBM FileNet Business Process Manager 4.5.1 through 5.1.0, FileNet Content Manager 4.5.1 through 5.2.0, and Case Foundation 5.2.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. Vulnerabilidad de XSS en FileNet P8 Platform Documentation Installable Info Center 4.5.1 hasta la versión 5.2.0 en IBM FileNet Business Process Manager 4.5.1 hasta 5.1.0, FileNet Content Manager 4.5.1 hasta la versión 5.2.0, y Case Foundation 5.2.0 permite a atacantes remotos inyectar script Web arbitrario o HTML a través de vectores no especificados. • http://secunia.com/advisories/56500 http://www.ibm.com/support/docview.wss?uid=swg21662360 http://www.securityfocus.com/bid/65045 https://exchange.xforce.ibmcloud.com/vulnerabilities/89862 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •