CVE-2014-9559 Information

Description

Cross-site scripting (XSS) vulnerability in SnipSnap 0.5.2a 1.0b1 and 1.0b2 allows remote attackers to inject arbitrary web script or HTML via the query parameter to /snipsnap-search.

Reference

http://seclists.org/fulldisclosure/2015/Feb/1 http://tetraph.com/security/cves/cve-2014-9559-snipsnap-xss-cross-site-scripting-security-vulnerabilities/

Share on: