CVE-2013-5966: XSS
Published Nov 19, 2013
·Updated
Cross-site scripting (XSS) vulnerability in ZK Framework before 5.0.13 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
14 affected components
Zkoss Zk Framework<=5.0.12
Zkoss Zk Framework=5.0.0
Zkoss Zk Framework=5.0.1
Zkoss Zk Framework=5.0.2
Zkoss Zk Framework=5.0.3
Zkoss Zk Framework=5.0.4
Zkoss Zk Framework=5.0.5
Zkoss Zk Framework=5.0.6
Zkoss Zk Framework=5.0.7
Zkoss Zk Framework=5.0.7.1
Zkoss Zk Framework=5.0.8
Zkoss Zk Framework=5.0.9
Zkoss Zk Framework=5.0.10
Zkoss Zk Framework=5.0.11
Event History
Nov 19, 2013
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-5966?
CVE-2013-5966 is considered to be a moderate severity vulnerability due to its potential for remote code execution via cross-site scripting.
2
How do I fix CVE-2013-5966?
To fix CVE-2013-5966, upgrade the ZK Framework to version 5.0.13 or later.
3
Which versions of ZK Framework are affected by CVE-2013-5966?
CVE-2013-5966 affects ZK Framework versions prior to 5.0.13, including all versions from 5.0.0 to 5.0.12.
4
What type of vulnerability is CVE-2013-5966?
CVE-2013-5966 is a cross-site scripting (XSS) vulnerability that allows attackers to inject arbitrary web scripts or HTML.
5
Can CVE-2013-5966 be exploited remotely?
Yes, CVE-2013-5966 can be exploited remotely, allowing attackers to execute malicious scripts in the context of the user's session.