CVE-2013-4275
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
Cross-site scripting (XSS) vulnerability in the zen_breadcrumb function in template.php in the Zen theme 6.x-1.x, 7.x-3.x before 7.x-3.2, and 7.x-5.x before 7.x-5.4 for Drupal allows remote authenticated users with the "administer themes" permission to inject arbitrary web script or HTML via the breadcrumb separator field.
Vulnerabilidad de tipo Cross-Site Scripting (XSS) en la función zen_breadcrumb en el archivo template.php en el tema Zen versiones 6.x-1.x, versiones 7.x-3.x anteriores a la versión 7.x-3.2 y versiones 7.x-5.x anteriores a la versión 7.x-5.4 para Drupal, permite a usuarios autenticados remotos con el permiso "administer themes" para inyectar script web o HTML arbitrario por medio del campo breadcrumb separator.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2013-06-12 CVE Reserved
- 2019-11-13 CVE Published
- 2024-08-06 CVE Updated
- 2024-08-06 First Exploit
- 2024-11-06 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (8)
URL | Tag | Source |
---|---|---|
http://www.openwall.com/lists/oss-security/2013/08/22/2 | Mailing List | |
http://www.securityfocus.com/bid/61922 | Broken Link | |
https://drupal.org/node/2071055 | Release Notes | |
https://drupal.org/node/2071065 | Release Notes | |
https://drupal.org/node/2071157 | Third Party Advisory | |
https://drupal.org/node/754000 | Third Party Advisory |
URL | Date | SRC |
---|---|---|
http://seclists.org/fulldisclosure/2013/Aug/226 | 2024-08-06 | |
http://www.madirish.net/?article=452 | 2024-08-06 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Zen Project Search vendor "Zen Project" | Zen Search vendor "Zen Project" for product "Zen" | >= 6.x-1.0 <= 6.x-1.3 Search vendor "Zen Project" for product "Zen" and version " >= 6.x-1.0 <= 6.x-1.3" | drupal |
Affected
| ||||||
Zen Project Search vendor "Zen Project" | Zen Search vendor "Zen Project" for product "Zen" | >= 7.x-3.0 < 7.x-3.2 Search vendor "Zen Project" for product "Zen" and version " >= 7.x-3.0 < 7.x-3.2" | drupal |
Affected
| ||||||
Zen Project Search vendor "Zen Project" | Zen Search vendor "Zen Project" for product "Zen" | >= 7.x-5.0 < 7.x-5.4 Search vendor "Zen Project" for product "Zen" and version " >= 7.x-5.0 < 7.x-5.4" | drupal |
Affected
|