Multiple cross-site scripting (XSS) vulnerabilities in EMC Documentum Web Development Kit (WDK) before 6.8 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4635
Reference (s):
- BUGTRAQ:20150105 ESA-2014-180: EMC Documentum Web Development Kit Multiple Vulnerabilities
- URL: http://archives.neohapsis.com/archives/bugtraq/2015-01/0009.html
- http://packetstormsecurity.com/files/129822/EMC-Documentum-Web-Development-Kit-XSS-CSRF-Redirection-Injection.html
- SECTRACK:1031497
- URL: http://www.securitytracker.com/id/1031497