Vulnerability Description
Multiple cross-site scripting (XSS) vulnerabilities in pd-admin before 4.17 allow remote authenticated users to inject arbitrary web script or HTML via (1) the WebFTP Overview "Create new directory" field or (2) the body of an e-mail autoresponder message.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Pd-Admin | Pd-Admin | <= 4.16 |
Related Weaknesses (CWE)
References
- http://www.kb.cert.org/vuls/id/311644US Government Resource
- http://www.pdadmin-forum.de/thread.php?threadid=4051
- http://www.kb.cert.org/vuls/id/311644US Government Resource
- http://www.pdadmin-forum.de/thread.php?threadid=4051
FAQ
What is CVE-2013-0129?
CVE-2013-0129 is a vulnerability with a CVSS score of 3.5 (LOW). Multiple cross-site scripting (XSS) vulnerabilities in pd-admin before 4.17 allow remote authenticated users to inject arbitrary web script or HTML via (1) the WebFTP Overview "Create new directory" f...
How severe is CVE-2013-0129?
CVE-2013-0129 has been rated LOW with a CVSS base score of 3.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2013-0129?
Check the references section above for vendor advisories and patch information. Affected products include: Pd-Admin Pd-Admin.