Cross-site scripting (XSS) vulnerability in Collabtive 1.2 allows remote authenticated users to inject arbitrary web script or HTML via the desc parameter in an Add project (addpro) action to admin.php.
References
Link | Resource |
---|---|
http://www.exploit-db.com/exploits/33250 | Exploit |
http://www.securityfocus.com/bid/67343 |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2014-05-15T14:00:00
Updated: 2015-05-12T18:57:00
Reserved: 2014-05-06T00:00:00
Link: CVE-2014-3247
JSON object: View
NVD Information
Status : Analyzed
Published: 2014-05-15T14:55:07.467
Modified: 2015-08-01T01:38:14.477
Link: CVE-2014-3247
JSON object: View
Redhat Information
No data.
CWE