CVE-2013-2137
Apache OFBiz Cross Site Scripting
Summary
Descriptions
Cross-site scripting (XSS) vulnerability in the "View Log" screen in the Webtools application in Apache Open For Business Project (aka OFBiz) 10.04.01 through 10.04.05, 11.04.01 through 11.04.02, and 12.04.01 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Vulnerabilidad Cross-site scripting (XSS) en la pantalla "View Log" en la aplicaciĆ³n Webtools en Apache Open For Business Project (tambiĆ©n conocido como OFBiz) v10.04.01 hasta v10.04.05, v11.04.01 hasta v11.04.02, y v12.04.01, permite a atacantes remotos inyectar web scripts arbitrarios o HTML mediante vectores desconocidos.
Apache OFBiz versions 10.04.01 through 10.04.05, 11.04.01 thorough 11.04.02, and 12.04.01 suffer from a cross site scripting vulnerability.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2013-02-19 CVE Reserved
- 2013-07-20 CVE Published
- 2024-08-06 CVE Updated
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
Threat Intelligence Resources (1)
Select | Title | Date |
---|---|---|
Apache OFBiz Cross Site Scripting | 2013-07-20 |
Select an advisory to view details here.
Select | Title | Date |
---|
Select an exploit to view details here.
References (6)
URL | Tag | Source |
---|---|---|
http://archives.neohapsis.com/archives/bugtraq/2013-07/0144.html | Broken Link | |
http://osvdb.org/95523 | Broken Link | |
http://secunia.com/advisories/53910 | Third Party Advisory | |
http://www.securityfocus.com/bid/61370 | Third Party Advisory | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/85874 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://ofbiz.apache.org/download.html#vulnerabilities | 2018-05-18 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Apache Search vendor "Apache" | Ofbiz Search vendor "Apache" for product "Ofbiz" | 10.04.01 Search vendor "Apache" for product "Ofbiz" and version "10.04.01" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Ofbiz Search vendor "Apache" for product "Ofbiz" | 10.04.02 Search vendor "Apache" for product "Ofbiz" and version "10.04.02" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Ofbiz Search vendor "Apache" for product "Ofbiz" | 10.04.03 Search vendor "Apache" for product "Ofbiz" and version "10.04.03" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Ofbiz Search vendor "Apache" for product "Ofbiz" | 10.04.04 Search vendor "Apache" for product "Ofbiz" and version "10.04.04" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Ofbiz Search vendor "Apache" for product "Ofbiz" | 10.04.05 Search vendor "Apache" for product "Ofbiz" and version "10.04.05" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Ofbiz Search vendor "Apache" for product "Ofbiz" | 11.04.01 Search vendor "Apache" for product "Ofbiz" and version "11.04.01" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Ofbiz Search vendor "Apache" for product "Ofbiz" | 11.04.02 Search vendor "Apache" for product "Ofbiz" and version "11.04.02" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Ofbiz Search vendor "Apache" for product "Ofbiz" | 12.04.01 Search vendor "Apache" for product "Ofbiz" and version "12.04.01" | - |
Affected
|