Candidate: CVE-2013-4556 PublicDate: 2013-11-18 02:55:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4556 http://www.openwall.com/lists/oss-security/2013/11/10/4 Description: Cross-site scripting (XSS) vulnerability in the author page (prive/formulaires/editer_auteur.php) in SPIP before 2.1.24 and 3.0.x before 3.0.12 allows remote attackers to inject arbitrary web script or HTML via the url_site parameter. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: Patches_spip: upstream: http://core.spip.org/projects/spip/repository/revisions/20880 (2.1.24) upstream: http://core.spip.org/projects/spip/repository/revisions/20879 (3.0.12) upstream_spip: released (2.1.24, 3.0.12) lucid_spip: ignored (reached end-of-life) precise_spip: ignored (reached end-of-life) precise/esm_spip: DNE (precise was needed) quantal_spip: ignored (reached end-of-life) raring_spip: ignored (reached end-of-life) saucy_spip: ignored (reached end-of-life) trusty_spip: not-affected (3.0.14-1) trusty/esm_spip: DNE (trusty was not-affected [3.0.14-1]) utopic_spip: ignored (reached end-of-life) vivid_spip: ignored (reached end-of-life) vivid/stable-phone-overlay_spip: DNE vivid/ubuntu-core_spip: DNE wily_spip: ignored (reached end-of-life) xenial_spip: not-affected (3.0.14-1) yakkety_spip: ignored (reached end-of-life) zesty_spip: ignored (reached end-of-life) artful_spip: ignored (reached end-of-life) bionic_spip: not-affected (3.0.14-1) cosmic_spip: not-affected (3.0.14-1) devel_spip: not-affected (3.0.14-1)