CVE-2011-5040

Multiple cross-site scripting (XSS) vulnerabilities in Infoproject Biznis Heroj allow remote attackers to inject arbitrary web script or HTML via the config parameter to (1) nalozi_naslov.php and (2) widget.dokumenti_lista.php.
Configurations

Configuration 1 (hide)

cpe:2.3:a:infoproject:biznis_heroj:*:*:*:*:*:*:*:*

History

21 Nov 2024, 01:33

Type Values Removed Values Added
References () http://www.exploit-db.com/exploits/18259 - Exploit () http://www.exploit-db.com/exploits/18259 - Exploit
References () http://www.zeroscience.mk/en/vulnerabilities/ZSL-2011-5064.php - Exploit () http://www.zeroscience.mk/en/vulnerabilities/ZSL-2011-5064.php - Exploit
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/71928 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/71928 -

Information

Published : 2011-12-30 19:55

Updated : 2025-04-11 00:51


NVD link : CVE-2011-5040

Mitre link : CVE-2011-5040

CVE.ORG link : CVE-2011-5040


JSON object : View

Products Affected

infoproject

  • biznis_heroj
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')