Vulnerability CVE-2008-3715


Published: 2008-08-19   Modified: 2012-02-12

Description:
Cross-site scripting (XSS) vulnerability in inc-core-admin-editor-previouscolorsjs.php in the FlexCMS 2.5 and earlier, when register_globals is enabled, allows remote attackers to inject arbitrary web script or HTML via the PreviousColorsString parameter.

See advisories in our WLB2 database:
Topic
Author
Date
Low
FlexCMS <= 2.5 Cross Site Scripting Vulnerability
irancrash
16.08.2008

Type:

CWE-79

(Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'))

Vendor: Flexcms
Product: Flexcms 
Version: 2.5; 2.0;

CVSS2 => (AV:N/AC:H/Au:N/C:N/I:P/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
2.6/10
2.9/10
4.9/10
Exploit range
Attack complexity
Authentication
Remote
High
No required
Confidentiality impact
Integrity impact
Availability impact
None
Partial
None

 References:
http://securityreason.com/securityalert/4166
http://www.securityfocus.com/archive/1/495508/100/0/threaded
http://www.securityfocus.com/bid/30709
https://exchange.xforce.ibmcloud.com/vulnerabilities/44521

Related CVE
CVE-2012-1901
Multiple cross-site request forgery (CSRF) vulnerabilities in FlexCMS 3.2.1 and earlier allow remote attackers to (1) hijack the authentication of users for requests that change account settings via a request to index.php/profile-edit-save or (2) hij...
CVE-2009-1256
SQL injection vulnerability in FlexCMS 2.5 allows remote attackers to execute arbitrary SQL commands via the ItemId parameter. NOTE: some of these details are obtained from third party information.
CVE-2009-0534
SQL injection vulnerability in FlexCMS allows remote attackers to execute arbitrary SQL commands via the catId parameter.

Copyright 2019, cxsecurity.com

 

Back to Top