Description
Multiple cross-site scripting (XSS) vulnerabilities in Dotclear before 2.4.2 allow remote attackers to inject arbitrary web script or HTML via the (1) login_data parameter to admin/auth.php; (2) nb parameter to admin/blogs.php; (3) type, (4) sortby, (5) order, or (6) status parameters to admin/comments.php; or (7) page parameter to admin/plugin.php.
Remediation
References
Related Vulnerabilities
OpenSSL Resource Management Errors Vulnerability (CVE-2014-3507)
Plone CMS Resource Management Errors Vulnerability (CVE-2012-5499)
WordPress Plugin WP Advanced Importer Cross-Site Scripting (2.1.1)
Internet Information Services Other Vulnerability (CVE-2003-0223)
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2015-5266)