// For flags

CVE-2014-8069

Pagekit 0.8.7 Cross Site Scripting / Open Redirect

Time Line
Published
2024-03-19
Updated
2024-03-19
Firt exploit
2024-03-19
Overview
Descriptions (3)
NVD, NVD, PS
CWE (1)
CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC (-)
Risk
CVSS Score
6.1 Medium
SSVC
-
KEV
-
EPSS
0.1%
Affected Products (-)
Vendors (1)
yootheme
Products (1)
pagekit
Versions (1)
0.8.7
Intel Resources (1)
Advisories (-)
-
Exploits (1)
PacketStorm
Plugins (-)
-
References (2)
General (1)
packetstormsecurity
Exploits & POcs (1)
packetstorm
Patches (-)
Advisories (-)
Summary
Descriptions

Multiple cross-site scripting (XSS) vulnerabilities in YOOtheme Pagekit CMS 0.8.7 allow remote attackers to inject arbitrary web script or HTML via the (1) HTTP Referer header to index.php/user or (2) PATH_INFO to index.php.

MĂșltiples vulnerabilidades de XSS en YOOtheme Pagekit CMS 0.8.7 permiten a atacantes remotos inyectar secuencias de comandos web o HTML arbitrarios a travĂ©s de (1) la cabecera HTTP Referer en index.php/user o (2) PATH_INFO en index.php.

Pagekit version 0.8.7 suffers from cross site scripting and open redirect vulnerabilities.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
None
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2014-10-09 CVE Reserved
  • 2014-10-13 CVE Published
  • 2014-10-13 First Exploit
  • 2023-03-07 EPSS Updated
  • 2024-08-06 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
Threat Intelligence Resources (1)
Security Advisory details:

Select an advisory to view details here.

Select an exploit to view details here.

Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Yootheme
Search vendor "Yootheme"
Pagekit
Search vendor "Yootheme" for product "Pagekit"
0.8.7
Search vendor "Yootheme" for product "Pagekit" and version "0.8.7"
-
Affected