CVE-2011-5177: XSS
Multiple cross-site scripting (XSS) vulnerabilities in admin/controller.php in eSyndiCat Pro 2.3.05 allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to the admins (2) blocks, (3) articles, or (4) suggest-category; or (5) sort parameter to the search page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-5177?
CVE-2011-5177 is a high severity vulnerability that allows remote attackers to exploit multiple cross-site scripting (XSS) vulnerabilities.
How do I fix CVE-2011-5177?
To fix CVE-2011-5177, you should update eSyndiCat Pro to version 2.3.06 or later, which resolves these XSS vulnerabilities.
Which versions of eSyndiCat are affected by CVE-2011-5177?
CVE-2011-5177 affects eSyndiCat Pro version 2.3.05 and earlier versions.
What parameters are exploited in CVE-2011-5177?
CVE-2011-5177 can be exploited through the id parameter on admins, blocks, articles, suggest-category, and the sort parameter on the search page.
Is user input safety compromised by CVE-2011-5177?
Yes, CVE-2011-5177 compromises user input safety by allowing attackers to inject arbitrary web scripts or HTML, resulting in cross-site scripting.