CVE-2014-3974: XSS
Published Jun 5, 2014
·Updated
Cross-site scripting (XSS) vulnerability in filemanager.php in AuraCMS 3.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the viewdir parameter.
Affected Software
1 affected component
AuraCMS AuraCMS<=3.0
Event History
Jun 5, 2014
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Data Sourced
via NVD·05:55 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2014-3974?
CVE-2014-3974 is classified as a cross-site scripting (XSS) vulnerability, which is considered high severity due to its potential for exploitation.
2
How do I fix CVE-2014-3974?
To fix CVE-2014-3974, it is recommended to update AuraCMS to a version later than 3.0.
3
What versions of AuraCMS are affected by CVE-2014-3974?
AuraCMS versions 3.0 and earlier are affected by CVE-2014-3974.
4
What type of vulnerability is CVE-2014-3974?
CVE-2014-3974 is a cross-site scripting (XSS) vulnerability.
5
Can an attacker exploit CVE-2014-3974 remotely?
Yes, an attacker can exploit CVE-2014-3974 remotely by injecting arbitrary web scripts or HTML through the viewdir parameter.