First published: Mon Jul 21 2014(Updated: )
Cross-site scripting (XSS) vulnerability in e107_admin/db.php in e107 2.0 alpha2 and earlier allows remote attackers to inject arbitrary web script or HTML via the type parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
e107 CMS | <=2.0 | |
e107 CMS | =2.0-alpha1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-4734 is classified as a medium severity vulnerability due to its impact on the security of the affected web applications.
To fix CVE-2014-4734, you should upgrade to a version of e107 later than 2.0 alpha2 that addresses this cross-site scripting vulnerability.
CVE-2014-4734 affects e107 versions 2.0 alpha2 and earlier, including 2.0-alpha1.
CVE-2014-4734 is a cross-site scripting (XSS) vulnerability allowing attackers to inject arbitrary web scripts or HTML.
Yes, CVE-2014-4734 can be exploited remotely by attackers to inject malicious scripts into affected web applications.