MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in BoltWire 3.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) "p" or (2) content parameter to index.php
Published Oct 23, 2013
4.3
MEDIUMCVSS 2.0
EPSS 2.15%
Description
Multiple cross-site scripting (XSS) vulnerabilities in BoltWire 3.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) "p" or (2) content parameter to index.php.
Affected products
No data.
OR
- ≤ 3.5
- 3.0
- 3.01
- 3.02
- 3.2.0
- 3.2.1
- 3.2.2
- 3.2.3
- 3.2.4
- 3.2.5
- 3.2.6
- 3.2.7
- 3.2.8
- 3.2.9
- 3.2.10
- 3.2.11
- 3.03
- 3.3
- 3.3.1
- 3.3.2
- 3.3.3
- 3.3.4
- 3.3.5
- 3.3.6
- 3.3.7
- 3.3.8
- 3.3.9
- 3.4
- 3.04
- 3.4.1
- 3.4.2
- 3.4.3
- 3.4.4
- 3.4.5
- 3.4.6
- 3.4.7
- 3.4.8
- 3.4.9
- 3.4.10
- 3.4.11
- 3.4.12
- 3.4.13
- 3.4.14
- 3.4.15
- 3.4.16
- 3.05
- 3.06
- 3.07
- 3.08
- 3.09
- 3.10
- 3.11
- 3.12
- 3.13
- 3.14
- 3.15
- 3.16
- 3.17
- 3.18
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (4)
- http://archives.neohapsis.com/archives/bugtraq/2013-10/0033.html mailing-listx_refsource_BUGTRAQExploit
- http://packetstormsecurity.com/files/123558 x_refsource_MISCExploit
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2013-2590 Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/87809 vdb-entryx_refsource_XF
| Link | Providers | Tags |
|---|---|---|
| http://archives.neohapsis.com/archives/bugtraq/2013-10/0033.html | mailing-listx_refsource_BUGTRAQExploit | |
| http://packetstormsecurity.com/files/123558 | x_refsource_MISCExploit | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2013-2590 | Advisory | |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/87809 | vdb-entryx_refsource_XF |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Oct 23, 2013
Updated Aug 6, 2024
Reserved Mar 22, 2013
Link CVE-2013-2651
CISA Vulnrichment
No data
Red Hat
No data
GitHub
No data