Get a Pentest and security assessment of your IT network.

2021-current

CVE-2015-1040 – Multiple cross-site scripting (XSS) vulnerabilities in the administrative

Multiple cross-site scripting (XSS) vulnerabilities in the administrative backend in BEdita 3.4.0 allow remote authenticated users to inject arbitrary web script or HTML via the (1) lrealname field in the editProfile form to index.php/home/profile; the (2) data[title] or (3) data[description] field in the addQuickItem form to index.php; the (4) “note text” field in the saveNote form to index.php/areas; or the (5) titleBEObject or (6) tagsArea field in the updateForm form to index.php/documents/view.

 

Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1040

Reference (s):

  • BID:71949
  • URL: http://www.securityfocus.com/bid/71949
  • https://github.com/bedita/bedita/issues/566
  • FULLDISC:20150108 Multiple persistent XSS vulnerabilites in CMS BEdita v. 3.4.0
  • URL: http://seclists.org/fulldisclosure/2015/Jan/16
Related posts
2021-current

CVE-2004-1715 - Directory traversal vulnerability in MIMEsweeper for Web before 5.0.4 all

2021-current

CVE-2014-4743 - Multiple cross-site scripting (XSS) vulnerabilities in (1) search_ajax.tp

2021-current

CVE-2014-9838 - magick/cache.c in ImageMagick 6.8.9-9 allows remote attackers to cause a

2021-current

CVE-2020-10447 - The way URIs are handled in admin/header.php in Chadha PHPKB Standard Mul