Description
Cross-site scripting (XSS) vulnerability in the Search feature in elka CMS (aka Elkapax) allows remote attackers to inject arbitrary web script or HTML via the q parameter to the default URI.
Exploits (1)
References (1)
Core 1
Core References
Third Party Advisory, VDB Entry mailing-list
x_refsource_bugtraq
http://www.securityfocus.com/archive/1/505725/100/0/threaded
Scores
EPSS
0.0016
EPSS Percentile
36.9%
Details
CWE
CWE-79
Status
published
Products (1)
elkagroup/elkapax_cms
Published
Aug 21, 2009
Tracked Since
Feb 18, 2026