CVE-2014-2710: XSS
Multiple cross-site scripting (XSS) vulnerabilities in Oliver (formerly Webshare) 1.3.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the PATHINFO to the (1) login page (index.php) or (2) login form (loginform-inc.php).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-2710?
CVE-2014-2710 is classified as a moderate severity vulnerability due to its potential for cross-site scripting attacks.
What are the affected versions for CVE-2014-2710?
CVE-2014-2710 affects versions of Oliver up to and including 1.3.1.
How do I fix CVE-2014-2710?
To fix CVE-2014-2710, upgrade Oliver to a version that is above 1.3.1 where the XSS vulnerabilities have been addressed.
What types of attacks can result from CVE-2014-2710?
CVE-2014-2710 allows remote attackers to perform cross-site scripting attacks by injecting arbitrary web scripts or HTML.
Where are the vulnerabilities located in CVE-2014-2710?
The vulnerabilities in CVE-2014-2710 are located in the PATH_INFO parameter of the login page and the login form.