VWE-2010-0077 Printable Version

https://www.vaultwiki.org/pages/Book/Documentation/VWE-2010-0077
This page is a chapter in Info Known Vulnerabilities

This page has been seen 169,976 times.

    • Created by on
      Last updated by on
Common NameReplacement Corruption Vulnerability
VWE-IDVWE-2010-0077
Related ReportNone
SeverityHIGH
Exploit DifficultyDifficult
PlatformAffects all platforms supported by the vulnerable versions.
DescriptionHTML/Javascript injection. Does not affect Lite versions.
DiscoveredNovember 20, 2010
ResolvedNovember 22, 2010
Patches Available3.0.6
2.5.7 Patch Level 4
WorkaroundRemove all URL replacements that paste the following characters " ' < > % /
The versions listed below are known to be affected by this issue. If you are using one of those versions, you should update to a newer release that has no known vulnerabilities.