CVE-2011-4565
Xoops < 2.5.1.a - XSS
Title source: ruleDescription
Multiple cross-site scripting (XSS) vulnerabilities in XOOPS 2.5.1.a, and possibly earlier versions, allow remote attackers to inject arbitrary web script or HTML via the (1) text parameter to include/formdhtmltextarea_preview.php or (2) img BBCODE tag within the message parameter to pmlite.php (aka Private Message). NOTE: some of these details are obtained from third party information.
References (6)
Scores
EPSS
0.0047
EPSS Percentile
64.6%
Classification
CWE
CWE-79
Status
published
Affected Products (31)
xoops/xoops
< 2.5.1.a
xoops/xoops
xoops/xoops
xoops/xoops
xoops/xoops
xoops/xoops
xoops/xoops
xoops/xoops
xoops/xoops
xoops/xoops
xoops/xoops
xoops/xoops
xoops/xoops
xoops/xoops
xoops/xoops
... and 16 more
Timeline
Published
Nov 28, 2011
Tracked Since
Feb 18, 2026