CVE-2011-0772 Information

Description

Multiple cross-site scripting (XSS) vulnerabilities in PivotX 2.2.0 and possibly other versions before 2.2.2 allow remote attackers to inject arbitrary web script or HTML via the (1) color parameter to includes/blogroll.php or (2) src parameter to includes/timwrapper.php.

Reference

http://blog.pivotx.net/archive/2011/01/11/pivotx-222-released http://pivot-weblog.svn.sf.net/viewvc/pivot-weblog?view=revision&revision=3409 http://pivot-weblog.svn.sf.net/viewvc/pivot-weblog?view=revision&revision=3410 http://secunia.com/advisories/43040 http://securityreason.com/securityalert/8062 http://www.htbridge.ch/advisory/xss_in_pivotx.html http://www.htbridge.ch/advisory/xss_in_pivotx_1.html http://www.osvdb.org/70673 http://www.osvdb.org/70674 http://www.securityfocus.com/archive/1/515958/100/0/threaded http://www.securityfocus.com/archive/1/515964/100/0/threaded http://www.securityfocus.com/bid/45996 https://exchange.xforce.ibmcloud.com/vulnerabilities/64975

Share on: