CVE-2014-3247
Published: 15 May 2014
Cross-site scripting (XSS) vulnerability in Collabtive 1.2 allows remote authenticated users to inject arbitrary web script or HTML via the desc parameter in an Add project (addpro) action to admin.php.
Priority
Status
Package | Release | Status |
---|---|---|
collabtive Launchpad, Ubuntu, Debian |
artful |
Does not exist
|
bionic |
Does not exist
|
|
cosmic |
Does not exist
|
|
disco |
Does not exist
|
|
lucid |
Does not exist
|
|
precise |
Ignored
(end of life)
|
|
quantal |
Ignored
(end of life)
|
|
saucy |
Ignored
(end of life)
|
|
trusty |
Does not exist
(trusty was needed)
|
|
upstream |
Released
(2.0)
|
|
utopic |
Ignored
(end of life)
|
|
vivid |
Not vulnerable
(2.0+dfsg-5)
|
|
wily |
Ignored
(end of life)
|
|
xenial |
Not vulnerable
(2.0+dfsg-5)
|
|
yakkety |
Not vulnerable
(2.0+dfsg-5)
|
|
zesty |
Does not exist
|