CVE-2014-8488 Information

Description

Cross-site scripting (XSS) vulnerability in the administrator panel in Yourls 1.7 allows remote attackers to inject arbitrary web script or HTML via a URL that is processed by the Shorten functionality.

Reference

http://lists.fedoraproject.org/pipermail/package-announce/2015-April/156526.html http://lists.fedoraproject.org/pipermail/package-announce/2015-April/156564.html http://lists.fedoraproject.org/pipermail/package-announce/2015-April/156596.html http://seclists.org/fulldisclosure/2014/Oct/111 20141025 Yourls XSS Stored Cross-site scripting (XSS) vulnerability in the administrator panel in Yourls 1.7 allows remote attackers to inject arbitrary web script or HTML via a URL that is processed by the Shorten functionality. cpe:2.3:a:yourls:yourls:1.7:::::::*

Share on: