CVE-2010-1724
Zikula Application Framework - XSS
Title source: ruleDescription
Multiple cross-site scripting (XSS) vulnerabilities in Zikula Application Framework 1.2.2, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) func parameter to index.php, or the (2) lang parameter to index.php, which is not properly handled by ZLanguage.php.
Exploits (2)
exploitdb
WORKING POC
VERIFIED
by High-Tech Bridge SA · textwebappsphp
https://www.exploit-db.com/exploits/33885
exploitdb
WORKING POC
VERIFIED
by High-Tech Bridge SA · textwebappsphp
https://www.exploit-db.com/exploits/33884
References (9)
Scores
EPSS
0.0287
EPSS Percentile
86.1%
Classification
CWE
CWE-79
Status
published
Affected Products (2)
zikula/zikula_application_framework
n/a/n/a
Timeline
Published
May 06, 2010
Tracked Since
Feb 18, 2026