CVE-2013-7351
Summary
| CVE | CVE-2013-7351 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-01-02 20:15:00 UTC |
| Updated | 2020-01-09 20:15:00 UTC |
| Description | Multiple cross-site scripting (XSS) vulnerabilities in index.php in Shaarli allow remote attackers to inject arbitrary web script or HTML via the URL to the (1) showRSS, (2) showATOM, or (3) showDailyRSS function; a (4) file name to the importFile function; or (5) vectors related to bookmarks. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Shaarli Project | Shaarli | - | All | All | All |
| Application | Shaarli Project | Shaarli | - | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| XSS flaw correction · sebsauvage/Shaarli@53da201 · GitHub | CONFIRM | github.com | Patch, Third Party Advisory |
| Multiples XSS in index.php · Issue #134 · sebsauvage/Shaarli · GitHub | CONFIRM | github.com | Exploit, Third Party Advisory |
| oss-sec: Re: CVE Request: Shaarli: Several XSS in index.php | MISC | seclists.org | Exploit, Mailing List, Patch, Third Party Advisory |
| IBM X-Force Exchange | MISC | exchange.xforce.ibmcloud.com | Third Party Advisory, VDB Entry |
| oss-sec: CVE Request: Shaarli: Several XSS in index.php | MISC | seclists.org | Exploit, Mailing List, Patch, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.