4.3
CVSSv2

CVE-2013-7351

Published: 02/01/2020 Updated: 09/01/2020
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in index.php in Shaarli allow remote malicious users to inject arbitrary web script or HTML via the URL to the (1) showRSS, (2) showATOM, or (3) showDailyRSS function; a (4) file name to the importFile function; or (5) vectors related to bookmarks.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

shaarli project shaarli -

Vendor Advisories

Debian Bug report logs - #743252 Multiples XSS in indexphp (CVE-2013-7351) Package: shaarli; Maintainer for shaarli is Debian PHP PEAR Maintainers <pkg-php-pear@listsaliothdebianorg>; Source for shaarli is src:shaarli (PTS, buildd, popcon) Reported by: David Prévot <taffit@debianorg> Date: Mon, 31 Mar 2014 22:4 ...