CVE-2013-6808: XSS
Published Dec 28, 2013
·Updated
Cross-site scripting (XSS) vulnerability in lib/NSSDropoff.php in ZendTo before 4.11-13 allows remote attackers to inject arbitrary web script or HTML via a modified emailAddr field to pickup.php.
Affected Software
22 affected components
Zend ZendTo<=4.11-12
Zend ZendTo=4.00
Zend ZendTo=4.01
Zend ZendTo=4.02
Zend ZendTo=4.03-3
Zend ZendTo=4.05-2
Zend ZendTo=4.06-2
Zend ZendTo=4.07-1
Zend ZendTo=4.08-4
Zend ZendTo=4.09-1
Zend ZendTo=4.10-4
Zend ZendTo=4.10-5
Zend ZendTo=4.11-1
Zend ZendTo=4.11-2
Zend ZendTo=4.11-3
Zend ZendTo=4.11-4
Zend ZendTo=4.11-5
Zend ZendTo=4.11-7
Zend ZendTo=4.11-8
Zend ZendTo=4.11-9
Zend ZendTo=4.11-10
Zend ZendTo=4.11-11
Event History
Dec 28, 2013
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Data Sourced
via NVD·04:53 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2013-6808?
CVE-2013-6808 is rated as a medium severity vulnerability due to its potential for exploitation through cross-site scripting.
2
How do I fix CVE-2013-6808?
To fix CVE-2013-6808, upgrade ZendTo to version 4.11-13 or later, where the vulnerability has been addressed.
3
What software is affected by CVE-2013-6808?
CVE-2013-6808 affects multiple versions of ZendTo prior to 4.11-13.
4
What type of vulnerability is CVE-2013-6808?
CVE-2013-6808 is a cross-site scripting (XSS) vulnerability that allows injection of arbitrary web scripts or HTML.
5
Which file in ZendTo contains the vulnerability CVE-2013-6808?
CVE-2013-6808 is found in lib/NSSDropoff.php specifically related to the emailAddr field.