4.3
CVSSv2

CVE-2013-2294

Published: 30/01/2020 Updated: 31/01/2020
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in ViewGit prior to 0.0.7 allow remote repository users to inject arbitrary web script or HTML via a (1) tag name to the Shortlog table in templates/shortlog.php or branch name to the (2) Shortlog table in templates/shortlog.php or (3) Heads table in plates/summary.php.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

viewgit project viewgit

Exploits

Vulnerability Report Author: Matthew R Bucci <bucci@sasupennedu> Date: 18 March, 2013 CVE-2013-2294 Description of Vulnerability: ----------------------------- ViewGit "is a git web repository viewer that aims to be easy to set up and upgrade, light on dependencies, and comfortable to use" (viewgitfealdiaorg/) ViewGit conta ...
ViewGit version 006 suffers from multiple persistent cross site scripting vulnerabilities ...