Lucene search

K
cveMitreCVE-2014-9103
HistoryNov 26, 2014 - 3:59 p.m.

CVE-2014-9103

2014-11-2615:59:18
CWE-79
mitre
web.nvd.nist.gov
27
cve-2014-9103
xss
kunena
joomla
web script injection
html injection

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

6

Confidence

High

EPSS

0.002

Percentile

64.9%

Multiple cross-site scripting (XSS) vulnerabilities in the Kunena component before 3.0.6 for Joomla! allow remote attackers to inject arbitrary web script or HTML via the (1) index value of an array parameter or the filename parameter in the Content-Disposition header to the (2) file or (3) profile image upload functionality.

Affected configurations

Nvd
Node
kunenakunenaRange3.0.5joomla\!
VendorProductVersionCPE
kunenakunena*cpe:2.3:a:kunena:kunena:*:*:*:*:*:joomla\!:*:*

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

6

Confidence

High

EPSS

0.002

Percentile

64.9%

Related for CVE-2014-9103