RSS   Vulnerabilities for 'Ajenti'   RSS

2014-06-18
 
CVE-2014-4301

 

 
Multiple cross-site scripting (XSS) vulnerabilities in the respond_error function in routing.py in Eugene Pankov Ajenti before 1.2.21.7 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) resources.js or (2) resources.css in ajenti:static/, related to the traceback page.

 
2014-04-30
 
CVE-2014-2260

CWE-79
 

 
Cross-site scripting (XSS) vulnerability in plugins/main/content/js/ajenti.coffee in Eugene Pankov Ajenti 1.2.13 allows remote authenticated users to inject arbitrary web script or HTML via the command field in the Cron functionality.

 


Copyright 2017, cxsecurity.com

 

Back to Top