1 results (0.002 seconds)

CVSS: 4.3EPSS: 0%CPEs: 2EXPL: 0

Cross-site scripting (XSS) vulnerability in the errorAction method in the ActionController base class in TYPO3 Flow (formerly FLOW3) 1.1.x before 1.1.1 and 2.0.x before 2.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified input, which is returned in an error message. Vulnerabilidad de tipo cross-site scripting (XSS) en el método errorAction en la clase base ActionController en TYPO3 Flow (anteriormente FLOW3) versiones 1.1.x anteriores a 1.1.1 y versiones 2.0.x anteriores a 2.0.1, permite a los atacantes remotos inyectar script web o HTML arbitrario por medio de una entrada no especificada, que es devuelta en un mensaje de error. • http://osvdb.org/100825 http://secunia.com/advisories/55996 http://typo3.org/teams/security/security-bulletins/typo3-flow/typo3-flow-sa-2013-001 https://exchange.xforce.ibmcloud.com/vulnerabilities/89614 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •