Cross-site scripting (XSS) vulnerability in plugins/main/content/js/ajenti.coffee in Eugene Pankov Ajenti 1.2.13 allows remote authenticated users to inject arbitrary web script or HTML via the command field in the Cron functionality.
References
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2014-04-30T22:00:00
Updated: 2014-04-30T21:57:00
Reserved: 2014-02-28T00:00:00
Link: CVE-2014-2260
JSON object: View
NVD Information
Status : Analyzed
Published: 2014-04-30T23:58:26.733
Modified: 2014-05-01T15:42:19.917
Link: CVE-2014-2260
JSON object: View
Redhat Information
No data.
CWE