4.3

CVE-2013-5586

Exploit
Cross-site scripting (XSS) vulnerability in wikka.php in WikkaWiki before 1.3.4-p1 allows remote attackers to inject arbitrary web script or HTML via the wakka parameter to sql/.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
WikkawikiWikkawiki Version <= 1.3.4
WikkawikiWikkawiki Version1.0.0
WikkawikiWikkawiki Version1.0.1
WikkawikiWikkawiki Version1.0.2
WikkawikiWikkawiki Version1.0.3
WikkawikiWikkawiki Version1.0.4
WikkawikiWikkawiki Version1.0.5
WikkawikiWikkawiki Version1.0.6
WikkawikiWikkawiki Version1.1.0
WikkawikiWikkawiki Version1.1.2
WikkawikiWikkawiki Version1.1.3
WikkawikiWikkawiki Version1.1.3.1
WikkawikiWikkawiki Version1.1.3.2
WikkawikiWikkawiki Version1.1.3.3
WikkawikiWikkawiki Version1.1.3.4
WikkawikiWikkawiki Version1.1.3.5
WikkawikiWikkawiki Version1.1.3.6
WikkawikiWikkawiki Version1.1.3.7
WikkawikiWikkawiki Version1.1.3.8
WikkawikiWikkawiki Version1.1.3.9
WikkawikiWikkawiki Version1.1.4.0
WikkawikiWikkawiki Version1.1.5.0
WikkawikiWikkawiki Version1.1.5.1
WikkawikiWikkawiki Version1.1.5.2
WikkawikiWikkawiki Version1.1.5.3
WikkawikiWikkawiki Version1.1.5.4
WikkawikiWikkawiki Version1.1.6.0
WikkawikiWikkawiki Version1.1.6.1
WikkawikiWikkawiki Version1.1.6.2
WikkawikiWikkawiki Version1.1.6.3
WikkawikiWikkawiki Version1.1.6.4
WikkawikiWikkawiki Version1.1.6.5
WikkawikiWikkawiki Version1.1.6.6
WikkawikiWikkawiki Version1.1.6.7
WikkawikiWikkawiki Version1.3.1
WikkawikiWikkawiki Version1.3.2
WikkawikiWikkawiki Version1.3.3
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.73% 0.842
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

http://archives.neohapsis.com/archives/bugtraq/2013-09/0048.html
Exploit
http://docs.wikkawiki.org/WhatsNew134
http://osvdb.org/97183
http://packetstormsecurity.com/files/123196
Exploit
http://seclists.org/bugtraq/2013/Sep/47
Exploit
http://secunia.com/advisories/54790
Vendor Advisory
http://www.securityfocus.com/bid/62325
https://exchange.xforce.ibmcloud.com/vulnerabilities/87013
https://wush.net/trac/wikka/changeset/1896
Patch
Exploit
https://wush.net/trac/wikka/changeset/1900
Patch
Exploit
https://wush.net/trac/wikka/ticket/1152
https://wush.net/trac/wikka/ticket/1153
https://www.htbridge.com/advisory/HTB23170