CVE-2014-0334 Information

Description

Multiple cross-site scripting (XSS) vulnerabilities in CMS Made Simple allow remote authenticated users to inject arbitrary web script or HTML via (1) the group parameter to admin/addgroup.php (2) the htmlblob parameter to admin/addhtmlblob.php the (3) title or (4) url parameter to admin/addbookmark.php (5) the stylesheet_name parameter to admin/copystylesheet.php (6) the template_name parameter to admin/copytemplate.php the (7) title or (8) url parameter to admin/editbookmark.php (9) the template parameter to admin/listtemplates.php or (10) the css_name parameter to admin/listcss.php a different issue than CVE-2014-2092.

Reference

http://www.kb.cert.org/vuls/id/526062 http://www.securityfocus.com/bid/65898 Multiple cross-site scripting (XSS) vulnerabilities in CMS Made Simple allow remote authenticated users to inject arbitrary web script or HTML via (1) the group parameter to admin/addgroup.php (2) the htmlblob parameter to admin/addhtmlblob.php the (3) title or (4) url parameter to admin/addbookmark.php (5) the stylesheet_name parameter to admin/copystylesheet.php (6) the template_name parameter to admin/copytemplate.php the (7) title or (8) url parameter to admin/editbookmark.php (9) the template parameter to admin/listtemplates.php or (10) the css_name parameter to admin/listcss.php a different issue than CVE-2014-2092.

Share on: