icon

We found results for “

WS-2013-0008

Good to know:

icon

Date: May 1, 2013

Cross-site-scripting (XSS) vulnerability allows an attacker to control the contents of the hash on the URL to run code in jQuery.Migrate before 1.2.0.

Language: JS

Severity Score

Severity Score

Weakness Type (CWE)

Code

CWE-17

Top Fix

icon

Upgrade Version

Upgrade to version idavoll/adminlte-theme - dev-dependabot/npm_and_yarn/datatables.net-1.10.22;idavoll/adminlte-theme - 3.5.0;idavoll/adminlte-theme - dev-dependabot/npm_and_yarn/Themes/Flatly/bootstrap-3.4.1;idavoll/adminlte-theme - 3.0.1;idavoll/adminlte-theme - no_fix;idavoll/adminlte-theme - 3.5.1;idavoll/adminlte-theme - 3.0.0;idavoll/adminlte-theme - 2.0.1;idavoll/adminlte-theme - dev-dependabot/npm_and_yarn/moment-2.29.2;idavoll/adminlte-theme - 1.0.0;idavoll/adminlte-theme - 2.0.0;jadu/pulsar - dev-dependabot/npm_and_yarn/path-parse-1.0.7;jadu/pulsar - 1.0.17;jadu/pulsar - v1.0.3;jadu/pulsar - 1.0.9;jadu/pulsar - dev-Stanton-patch-1;sheillendra/yii2-bootswatch - v3.1.1;sheillendra/yii2-bootswatch - v3.2.0;sheillendra/yii2-bootswatch - v3.1.0;sheillendra/yii2-bootswatch - no_fix;sheillendra/yii2-bootswatch - v3.0.3;sheillendra/yii2-bootswatch - v3.0.2;imagina/imaginacmsadmin-theme - 1.9.0;arthurgroup/websitebuilder - dev-newsletter_module;arthurgroup/websitebuilder - dev-fix_backup_encoding_v2;arthurgroup/websitebuilder - 1.1.8.x-dev;arthurgroup/websitebuilder - 1.0.10.x-dev;arthurgroup/websitebuilder - dev-contact_form_fix_sr-1;arthurgroup/websitebuilder - 0.93;arthurgroup/websitebuilder - 1.1.11.x-dev;arthurgroup/websitebuilder - dev-tg;arthurgroup/websitebuilder - dev-admin_redesign;arthurgroup/websitebuilder - 1.1.1.x-dev;arthurgroup/websitebuilder - dev-custom_field_button;arthurgroup/websitebuilder - dev-1.2-test-pm;arthurgroup/websitebuilder - dev-update_custom_fields_design;thomaspark/bootswatch - v4.0.0;thomaspark/bootswatch - v4.6.0;thomaspark/bootswatch - v3.0.3;thomaspark/bootswatch - v4.1.0;thomaspark/bootswatch - v5.1.3;thomaspark/bootswatch - dev-dependabot/npm_and_yarn/grunt-1.5.3;thomaspark/bootswatch - v3.2.0;thomaspark/bootswatch - v3.1.0;thomaspark/bootswatch - v4.2.1;thomaspark/bootswatch - v3.1.1;thomaspark/bootswatch - v3.3.4;thomaspark/bootswatch - v5.x-dev;thomaspark/bootswatch - v3.3.1;thomaspark/bootswatch - v3.3.6;thomaspark/bootswatch - v3.3.5;thomaspark/bootswatch - v3.0.2;thomaspark/bootswatch - no_fix;thomaspark/bootswatch - v3.4.0;gaomingcode/jquery - 1.10.1;gaomingcode/jquery - 1.12.0;gaomingcode/jquery - 2.1.0;perminder-klair/yii2-sir-trevor-js - no_fix;rcm/dynamic-navigation - 0.1.2;tinindja/microweber-for-laravel-5.8 - 0.93;tinindja/microweber-for-laravel-5.8 - no_fix;tinindja/microweber-for-laravel-5.8 - oop-preview;denisgold/adminlte-theme - 1.0.0;denisgold/adminlte-theme - 2.0.1;denisgold/adminlte-theme - 3.0.0;denisgold/adminlte-theme - 3.0.1;denisgold/adminlte-theme - 2.5.0;denisgold/adminlte-theme - no_fix;slub/slub-web-kartenforum - dev-dependabot/npm_and_yarn/Build/minimist-1.2.6;slub/slub-web-kartenforum - dev-dependabot/npm_and_yarn/Build/terser-5.14.2;slub/slub-web-kartenforum - dev-dev-integrate-mosaic-maps;slub/slub-web-kartenforum - dev-dependabot/npm_and_yarn/Build/vk2/follow-redirects-1.14.8;slub/slub-web-kartenforum - dev-dependabot/npm_and_yarn/Build/vk2/karma-6.3.14;slub/slub-web-kartenforum - dev-develop-fixes;slub/slub-web-kartenforum - v3.0.0;yewei-cao/noodle - dev-dependabot/npm_and_yarn/y18n-3.2.2;yewei-cao/noodle - dev-feature/admin;yewei-cao/noodle - v0.0.31;yewei-cao/noodle - v0.03;amulen/amulen - 0.1.0;synergy/pagebuilder - v1.1;synergy/pagebuilder - v3.2.0;synergy/pagebuilder - dev-dependabot/composer/laminas/laminas-i18n-resources-2.8.0;synergy/pagebuilder - dev-dependabot/composer/laminas/laminas-server-2.11.1;synergy/pagebuilder - v6.1.0;synergy/pagebuilder - dev-dependabot/composer/laminas/laminas-component-installer-2.6.0;synergy/pagebuilder - v1.0;synergy/pagebuilder - dev-dependabot/composer/guzzlehttp/psr7-2.2.1;synergy/pagebuilder - v3.0.0;synergy/pagebuilder - dev-dependabot/composer/monolog/monolog-1.26.1;synergy/pagebuilder - v2.0.0;newscoop/article-edit-screen - v1.2.0;newscoop/article-edit-screen - v1.0.1;newscoop/article-edit-screen - 1.0.0-alpha1;newscoop/article-edit-screen - v1.0.0-beta.11;newscoop/article-edit-screen - v1.0.0;newscoop/article-edit-screen - v1.1;informaticatrentina/pat_base - no_fix;informaticatrentina/pat_base - 1.7.0;informaticatrentina/pat_base - 1.5;qcubed/qcubed - no_fix;qcubed/qcubed - svn-1.1@218;qcubed/qcubed - v3.1.1;itlized/bootswatch - no_fix;dunglas/todomvc-bundle - 2.1.x-dev;dunglas/todomvc-bundle - v1.0.0;ewebcms/ewebcms - v1.0;odwini/asgardcms-adminlte - no_fix;UmbracoCms - 6.0.5;UmbracoCms - 4.11.8;evgenbel/platform - 1.0.1;evgenbel/platform - 2.0.1;evgenbel/platform - test;leantime/leantime - v2.1-beta;acs/acspanel-standard - dev-f/docker-image-52;microweber/microweber - 1.0.5-fix1;microweber/microweber - dev-Radanovn-patch-1;microweber/microweber - 1.0.4-fixed;microweber/microweber - dev-master;microweber/microweber - dev-daisy-ui-bug;microweber/microweber - 0.93;microweber/microweber - dev-new-source-editor;microweber/microweber - dev-laravel-sail;microweber/microweber - dev-1.2-dev;microweber/microweber - dev-revert-700-1.2;microweber/microweber - dev-lang-fix;microweber/microweber - dev-handles-2;microweber/microweber - dev-website-builder-from-json;microweber/microweber - dev-inline-spacings-replace;microweber/microweber - dev-backup_new_functions;microweber/microweber - dev-optimization;microweber/microweber - dev-theme_content_export;microweber/microweber - 1.0.7-fix1;microweber/microweber - 1.x-dev;microweber/microweber - v2.0.0;microweber/microweber - dev-php8;microweber/microweber - 1.2.1.x-dev;microweber/microweber - dev-slow_backup_fix;microweber/microweber - dev-optimization1;newscoop/scoopwriter - v1.1;newscoop/scoopwriter - 1.0.0-alpha1;newscoop/scoopwriter - v1.2.0;newscoop/scoopwriter - v1.0.1;newscoop/scoopwriter - v1.0.0-beta.11;newscoop/scoopwriter - v1.0.0;ns/smaller-color-admin-bundle - no_fix;bcscoder/admin-theme - no_fix;luxifer/dependensees - 1.0.0;luxifer/dependensees - no_fix;su-sws/open_framework - 6.x-1.0;su-sws/open_framework - 7.2.6;imagina/adminlte-theme - no_fix;imagina/adminlte-theme - 1.10.1;imagina/adminlte-theme - 3.0.2;imagina/adminlte-theme - 1.0.0;bootleg/cms - dev-themable;bootleg/cms - dev-dev_ssl;erwin32/nette-foundation-sandbox - no_fix;reliv/rcm-dynamic-navigation - 0.1.2;qoxcorp/exengine-core - no_fix;sunra/jquery-set-symfony2-bundle - no_fix;cu-system/cu_starterkit_theme - no_fix;php-nik/pm-bundle - v1.0.0;php-nik/pm-bundle - no_fix;php-nik/pm-bundle - v1.0.1;argoflo/qcubed - no_fix;asgardcms/platform - 1.8.0;asgardcms/platform - no_fix;asgardcms/platform - 1.0.1;asgardcms/platform - 2.0.0;asgardcms/platform - 1.15.0;asgardcms/platform - 1.0.0;asgardcms/platform - 2.0.1;asgardcms/platform - test;armoni/platform - 1.0.0;armoni/platform - 1.8.0;armoni/platform - no_fix;bitsoflove-asgard/adminlte - 1.0.0;bitsoflove-asgard/adminlte - 1.13.0;e282486518/yii2admin - v1.0.0;e282486518/yii2admin - no_fix;yk/laravel-blogs - no_fix;qcubed-4/qcubed-4 - no_fix;jjsoft-ar/platform - 1.7.0;jjsoft-ar/platform - no_fix;jjsoft-ar/platform - 1.0.0;tutomvc/tutomvc - 2.0.1;tutomvc/tutomvc - 3.0.1;tutomvc/tutomvc - dev-release/3.0.0;tutomvc/tutomvc - dev-release/2.0.0;darekmeco/platform - 1.0.1;darekmeco/platform - 1.7.0;darekmeco/platform - 1.15.0;darekmeco/platform - test;darekmeco/platform - no_fix;darekmeco/platform - 2.0.1;imagina/cms-platform - no_fix;imagina/cms-platform - 1.0.0;jjsoft-ar/adminlte-theme - 1.0.0;jjsoft-ar/adminlte-theme - no_fix;rueduphp/octo - dev-middlewares;notegame/asgardcms - 1.0.0;imaginacms/platform - no_fix;imaginacms/platform - 1.0.0;intelogie/jquery - 1.10.1;intelogie/jquery - 1.11.1;sagsoz06/adminlte-theme - no_fix;backbee/backbee - v0.11;groucho75/ci_html5_auth_crud - no_fix;soda-framework/bootlegcms - 1.0;javanile/vtiger-core - 7.5.0;bokeh - 0.8.0;bokeh - 0.6.1;bokeh - 0.5.2;webmodules/jquery - 1.11.1;webmodules/jquery - 1.10.1;asgardcms/adminlte-theme - 1.0.0;asgardcms/adminlte-theme - no_fix;runopencode/diem-extended - no_fix;viames/pair_boilerplate - dev-master;components/jquery - 1.10.1;components/jquery - 1.11.1;nzedb/nzedb - v0.6.0-RC5;nzedb/nzedb - v0.6.0-RC2;bdelamatre/delamatre-zend - no_fix;csanquer/fakery-generator - dev-wrong_modifier;guoyu/yii2admin - v1.0.0;guoyu/yii2admin - no_fix;capham/adminlte-theme - 1.0.0;capham/adminlte-theme - no_fix;bcscoder/jcheckout - no_fix;oakcms/oakcms - v0.0.1-alpha.0.1;oakcms/oakcms - no_fix;procoders/admin - 1.0.0;acosf/archersys - 1.0;congkhuong/laraveldesign - no_fix;wisnuwidi/lockname - no_fix;accunity/adminlte-theme - 0.1;yusidabcs/checkout - no_fix;Noodles.AspMvc - 1.1.423;tigefa4u/tigefa4u.github.io - v2.1.0;tigefa4u/tigefa4u.github.io - v3.3.0;tecnodesignc/adminlte-theme - no_fix;SP.Orchard - no_fix;jQuery.Migrate - 1.2.0;ns/color-admin-bundle - no_fix;ns/color-admin-bundle - 0.1.0;dmf/bootstrapcontent - 0.1.0;dmf/bootstrapcontent - no_fix;tonci/phonebook - no_fix;bitmannl/grocery-crud - v1.4;arx/arxmin - 5.0.1;kzima/slimbone - no_fix;g3n1us/editor - no_fix;keeko/bootstrap-design - no_fix;hillelcoren/invoice-ninja - v1.1.2;karlvr/consistent.js - no_fix;gallerymiriam/gallerymiriam - no_fix;laraviet/platform - no_fix;imagina/adminimagina - no_fix;vwlabs/vwadminlte-theme - no_fix;ipython - 2.0.0;azt3k/abc-silverstripe - 0.0.1;backbee/backbee-php - v0.11;org.webjars.npm:github-com-mozilla-nunjucks:no_fix;org.webjars:bootswatch:3.3.5+4;org.webjars:bootswatch:3.0.3+1;org.webjars:bootswatch:3.3.1+2;org.webjars.bowergithub.thomaspark:bootswatch:4.4.1;org.webjars.bowergithub.thomaspark:bootswatch:no_fix;org.webjars.npm:floatthead:2.0.3;org.webjars.bower:jquery:1.11.0;org.webjars.bower:jquery:2.1.0;org.webjars.bowergithub.jquery:jquery-dist:2.1.3;org.webjars.bowergithub.jquery:jquery-dist:1.11.0-rc1;org.webjars.bower:jQuery:2.1.0;org.webjars.npm:browser-jquery:no_fix;org.webjars.npm:github-com-thomaspark-bootswatch:no_fix;org.webjars.npm:bootswatch:3.3.6;org.webjars.npm:angular-timer:no_fix;org.webjars.npm:jquery:1.11.0

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): LOW
Privileges Required (PR): NONE
User Interaction (UI): REQUIRED
Scope (S): CHANGED
Confidentiality (C): LOW
Integrity (I): LOW
Availability (A): NONE

Do you need more information?

Contact Us