4.3
CVSSv2

CVE-2013-6168

Published: 14/11/2013 Updated: 29/08/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in Zikula Application Framework prior to 1.3.6 allows remote malicious users to inject arbitrary web script or HTML via the returnpage parameter to index.php.

Vulnerable Product Search on Vulmon Subscribe to Product

zikula zikula application framework 1.3.2

zikula zikula application framework 1.3.1

zikula zikula application framework 1.3.0

zikula zikula application framework

zikula zikula application framework 1.3.4

zikula zikula application framework 1.3.3

Exploits

Zikula version 135 build 20 suffers from a cross site scripting vulnerability ...