We found results for “”
CVE-2014-4913
Good to know:
Date: December 15, 2019
ZF2014-03 has a potential cross site scripting vector in multiple view helpers
Language: PHP
Severity Score
Related Resources (8)
Severity Score
Weakness Type (CWE)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CWE-79Top Fix
Upgrade Version
Upgrade to version pi/pi - v2.6.0-alpha1;vufind/vufind - dev-legacy/bundled-dependencies;vufind/vufind - dev-autocomplete-v2-1-10;vufind/vufind - RD1;vufind/vufind - dev-release-2.4;webino/zend-view - 2.3.4;webino/zend-view - release-2.2.3;webino/zend-view - release-2.0.7;webino/zend-view - release-2.2.9;webino/zend-view - release-2.2.7;webino/zend-view - release-2.2.8;webino/zend-view - release-2.2.0rc3;webino/zend-view - release-2.1.2;webino/zend-view - release-2.3.2;webino/zend-view - release-2.1.5;zendframework/zend-view - 2.2.0rc3;zendframework/zend-view - 2.1.2;zendframework/zend-view - 2.2.3;zendframework/zend-view - 2.0.7;zendframework/zend-view - 2.3.2;zendframework/zend-view - 2.2.7;zendframework/zend-view - 2.3.4;zendframework/zend-view - 2.1.5;zendframework/zendframework - release-2.0.0beta1;zendframework/zendframework - 2.3.4;vivaweb/zendframework - 2.3.4;vivaweb/zendframework - release-2.0.0beta1;zendframework/zend-form - 2.1.2;zendframework/zend-form - 2.2.7;zendframework/zend-form - 2.2.0rc3;zendframework/zend-form - 2.0.4;zendframework/zend-form - 2.3.1;zendframework/zend-form - 2.1.5;zendframework/zend-form - 2.0.7;zzh-php/lib - no_fix;obimet/tool_console - no_fix;webino/zend-form - 2.3.1;gotcms/gotcms - 1.5.2;torrentpier/torrentpier - v2.2.0;libra/libra-app - no_fix
CVSS v3.1
| Base Score: |
|
|---|---|
| Attack Vector (AV): | NETWORK |
| Attack Complexity (AC): | LOW |
| Privileges Required (PR): | NONE |
| User Interaction (UI): | REQUIRED |
| Scope (S): | CHANGED |
| Confidentiality (C): | LOW |
| Integrity (I): | LOW |
| Availability (A): | NONE |
CVSS v2
| Base Score: |
|
|---|---|
| Access Vector (AV): | NETWORK |
| Access Complexity (AC): | MEDIUM |
| Authentication (AU): | NONE |
| Confidentiality (C): | NONE |
| Integrity (I): | PARTIAL |
| Availability (A): | NONE |
| Additional information: |
Vulnerabilities
Projects
Contact Us


