Multiple cross-site scripting (XSS) vulnerabilities in Apache Roller before 5.0.2 allow remote attackers to inject arbitrary web script or HTML via vectors related to the search results in the (1) RSS and (2) Atom feed templates.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: redhat

Published: 2013-12-07T20:00:00

Updated: 2013-12-07T19:57:00

Reserved: 2013-06-12T00:00:00


Link: CVE-2013-4171

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2013-12-07T20:55:02.210

Modified: 2013-12-09T17:09:53.363


Link: CVE-2013-4171

JSON object: View

cve-icon Redhat Information

No data.

CWE