4.3

CVE-2013-4880

Exploit
Cross-site scripting (XSS) vulnerability in core/admin/modules/developer/modules/views/add.php in BigTree CMS 4.0 RC2 and earlier allows remote attackers to inject arbitrary web script or HTML via the module parameter.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
BigtreecmsBigtree Cms Updaterc2 Version <= 4.0
BigtreecmsBigtree Cms Version4.0 Updateb1
BigtreecmsBigtree Cms Version4.0 Updateb2
BigtreecmsBigtree Cms Version4.0 Updateb3
BigtreecmsBigtree Cms Version4.0 Updateb4
BigtreecmsBigtree Cms Version4.0 Updateb5
BigtreecmsBigtree Cms Version4.0 Updateb6
BigtreecmsBigtree Cms Version4.0 Updateb7
BigtreecmsBigtree Cms Version4.0 Updaterc1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.3% 0.869
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

http://archives.neohapsis.com/archives/bugtraq/2013-08/0039.html
Exploit
https://www.htbridge.com/advisory/HTB23165
Exploit
http://osvdb.org/96008
https://exchange.xforce.ibmcloud.com/vulnerabilities/86287
https://github.com/bigtreecms/BigTree-CMS/commit/8a59c2e13f8e151b6a9e98f73e641e1ec8d928df
Patch
Exploit