Candidate: CVE-2013-7351 PublicDate: 2020-01-02 20:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-7351 https://github.com/sebsauvage/Shaarli/commit/53da201749f8f362323ef278bf338f1d9f7a925a Description: Multiple cross-site scripting (XSS) vulnerabilities in index.php in Shaarli allow remote attackers to inject arbitrary web script or HTML via the URL to the (1) showRSS, (2) showATOM, or (3) showDailyRSS function; a (4) file name to the importFile function; or (5) vectors related to bookmarks. Ubuntu-Description: Notes: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=743252 Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N [6.1 MEDIUM] Patches_shaarli: upstream: https://github.com/sebsauvage/Shaarli/commit/53da201749f8f362323ef278bf338f1d9f7a925a upstream_shaarli: needed lucid_shaarli: DNE precise_shaarli: DNE quantal_shaarli: DNE saucy_shaarli: ignored (reached end-of-life) trusty_shaarli: not-affected (0.0.41betadfsg2-4) trusty/esm_shaarli: DNE (trusty was not-affected [0.0.41betadfsg2-4]) utopic_shaarli: ignored (reached end-of-life) vivid_shaarli: ignored (reached end-of-life) vivid/stable-phone-overlay_shaarli: DNE vivid/ubuntu-core_shaarli: DNE wily_shaarli: ignored (reached end-of-life) xenial_shaarli: not-affected (0.0.41betadfsg2-4) yakkety_shaarli: not-affected (0.0.41betadfsg2-4) devel_shaarli: DNE