Candidate: CVE-2014-4737 PublicDate: 2014-10-10 14:55:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4737 https://www.htbridge.com/advisory/HTB23223 http://xforce.iss.net/xforce/xfdb/96802 http://textpattern.com/weblog/379/textpattern-cms-457-released-ten-years-on http://packetstormsecurity.com/files/128519/Textpattern-4.5.5-Cross-Site-Scripting.html Description: Cross-site scripting (XSS) vulnerability in Textpattern CMS before 4.5.7 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to setup/index.php. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: Patches_textpattern: upstream_textpattern: released (4.5.7) lucid_textpattern: ignored (reached end-of-life) precise_textpattern: DNE trusty_textpattern: DNE trusty/esm_textpattern: DNE devel_textpattern: DNE