4.3
CVE-2013-3281
- EPSS 0.59%
- Published 06.11.2013 15:55:05
- Last modified 11.04.2025 00:51:21
- Source security_alert@emc.com
- Teams watchlist Login
- Open Login
Cross-site scripting (XSS) vulnerability in EMC Documentum Webtop before 6.7 SP2 P07, Documentum WDK before 6.7 SP2 P07, Documentum Taskspace before 6.7 SP2 P07, Documentum Records Manager before 6.7 SP2 P07, Documentum Web Publisher before 6.5 SP7, Documentum Digital Asset Manager before 6.5 SP6, Documentum Administrator before 6.7 SP2 P07, and Documentum Capital Projects before 1.8 P01 allows remote attackers to inject arbitrary web script or HTML via a crafted parameter in a URL.
Data is provided by the National Vulnerability Database (NVD)
Emc ≫ Documentum Taskspace Updatesp2 Version <= 6.7
Emc ≫ Documentum Taskspace Version6.7
Emc ≫ Documentum Taskspace Version6.7 Updatesp1
Emc ≫ Documentum Capital Projects Version <= 1.8
Emc ≫ Documentum Wdk Updatesp2 Version <= 6.7
Emc ≫ Documentum Wdk Version6.7
Emc ≫ Documentum Wdk Version6.7 Updatesp1
Emc ≫ Documentum Digital Asset Manager Updatesp5 Version <= 6.5
Emc ≫ Documentum Digital Asset Manager Version6.5
Emc ≫ Documentum Digital Asset Manager Version6.5 Updatesp1
Emc ≫ Documentum Digital Asset Manager Version6.5 Updatesp2
Emc ≫ Documentum Digital Asset Manager Version6.5 Updatesp3
Emc ≫ Documentum Digital Asset Manager Version6.5 Updatesp4
Emc ≫ Documentum Administrator Updatesp2 Version <= 6.7
Emc ≫ Documentum Administrator Version6.7
Emc ≫ Documentum Administrator Version6.7 Updatesp1
Emc ≫ Documentum Webtop Updatesp2 Version <= 6.7
Emc ≫ Documentum Webtop Version6.7
Emc ≫ Documentum Webtop Version6.7 Updatesp1
Emc ≫ Documentum Web Publisher Updatesp6 Version <= 6.5
Emc ≫ Documentum Web Publisher Version6.5
Emc ≫ Documentum Web Publisher Version6.5 Updatesp1
Emc ≫ Documentum Web Publisher Version6.5 Updatesp2
Emc ≫ Documentum Web Publisher Version6.5 Updatesp3
Emc ≫ Documentum Web Publisher Version6.5 Updatesp4
Emc ≫ Documentum Web Publisher Version6.5 Updatesp5
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.59% | 0.682 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:N/I:P/A:N
|
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.