4.3
CVSSv2

CVE-2012-5919

Published: 19/11/2012 Updated: 29/08/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in Havalite 1.0.4 and previous versions allow remote malicious users to inject arbitrary web script or HTML via the (1) find or (2) replace fields to havalite/findReplace.php; (3) username parameter to havalite/hava_login.php, (4) the Edit Article module, or (5) hava_post.php in the postAuthor module; (6) postId parameter to hava_post.php; (7) userId parameter to hava_user.php; or (8) linkId parameter to hava_link.php.

Vulnerable Product Search on Vulmon Subscribe to Product

havalite cms

Exploits

Title: ====== Havalite CMS v104 - Multiple Web Vulnerabilities Date: ===== 2012-04-23 References: =========== wwwvulnerability-labcom/get_contentphp?id=520 VL-ID: ===== 520 Introduction: ============= Havalite, a lightweight, open source CMS, based on php and SQLite It\\\\\\\'s licensed under the GNU General Public License - ...