Cross-site scripting (XSS) vulnerability in Apache Wicket 1.4.x prior to 1.4.18, when setAutomaticMultiWindowSupport is enabled, allows remote malicious users to inject arbitrary web script or HTML via unspecified parameters.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
apache wicket 1.4.14 |
||
apache wicket 1.4.12 |
||
apache wicket 1.4.6 |
||
apache wicket 1.4.17 |
||
apache wicket 1.4.0 |
||
apache wicket 1.4.3 |
||
apache wicket 1.4.15 |
||
apache wicket 1.4.9 |
||
apache wicket 1.4.8 |
||
apache wicket 1.4.5 |
||
apache wicket 1.4.2 |
||
apache wicket 1.4.11 |
||
apache wicket 1.4.1 |
||
apache wicket 1.4.10 |
||
apache wicket 1.4.16 |
||
apache wicket 1.4.13 |
||
apache wicket 1.4.7 |
||
apache wicket 1.4.4 |