4.3
CVSSv2

CVE-2013-4722

Published: 25/04/2014 Updated: 25/04/2014
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in Admin/login/default.asp in DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other versions allow remote malicious users to inject arbitrary web script or HTML via the (1) username, (2) url, (3) qstr parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

ddsn cm3 acora content management system 6.0.6\\/1a

ddsn cm3 acora content management system 6.0.2\\/1a

ddsn cm3 acora content management system 5.5.7\\/12b

ddsn cm3 acora content management system 5.5.0\\/1b-p1

Exploits

CM3 AcoraCMS versions 606/1a, 602/1a, 557/12b, and 550/1b-p1 suffer from cross site request forgery, cross site scripting, information disclosure, weak cookies, and URL redirection vulnerabilities ...