CVE-2013-6808
Published Dec 28, 2013
Last updated 11 years ago
Overview
- Description
- Cross-site scripting (XSS) vulnerability in lib/NSSDropoff.php in ZendTo before 4.11-13 allows remote attackers to inject arbitrary web script or HTML via a modified emailAddr field to pickup.php.
- Source
- cve@mitre.org
- NVD status
- Analyzed
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 4.3
- Impact score
- 2.9
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:N/I:P/A:N
Weaknesses
- nvd@nist.gov
- CWE-79
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:zend:zendto:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9E53876E-C0FC-4211-8AEC-3FE1575EC11B", "versionEndIncluding": "4.11-12" }, { "criteria": "cpe:2.3:a:zend:zendto:4.00:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E92086FD-7FE7-46E2-9430-87C78A0268AC" }, { "criteria": "cpe:2.3:a:zend:zendto:4.01:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2D84A13A-C889-4083-8441-1FE743847A3D" }, { "criteria": "cpe:2.3:a:zend:zendto:4.02:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8DB3EF67-4D08-4DDC-B601-5D9F00464694" }, { "criteria": "cpe:2.3:a:zend:zendto:4.03-3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "006D7A44-8573-4FF6-BBE7-8C9518E143CD" }, { "criteria": "cpe:2.3:a:zend:zendto:4.05-2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CA6D16A1-2481-4B47-A0FC-2FCF3153E47C" }, { "criteria": "cpe:2.3:a:zend:zendto:4.06-2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5381907E-1341-4884-BC66-40ACEEC8B101" }, { "criteria": "cpe:2.3:a:zend:zendto:4.07-1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "ABE0C7E6-B806-48E3-9F81-17A0929A4B0F" }, { "criteria": "cpe:2.3:a:zend:zendto:4.08-4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F58C02DF-F24C-46CC-A096-57A24446EB31" }, { "criteria": "cpe:2.3:a:zend:zendto:4.09-1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E025DC7D-5BF2-4B8D-97E3-6017C53FD82F" }, { "criteria": "cpe:2.3:a:zend:zendto:4.10-4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "91377F42-3AE7-465C-AF97-13F5E3062A9C" }, { "criteria": "cpe:2.3:a:zend:zendto:4.10-5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9D84D638-9921-45CD-961E-3DBC20516767" }, { "criteria": "cpe:2.3:a:zend:zendto:4.11-1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9BB5D444-17B1-4A66-AC98-9C9A85355310" }, { "criteria": "cpe:2.3:a:zend:zendto:4.11-2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C5F369D9-56FB-41F1-8D45-3565EBA98FF6" }, { "criteria": "cpe:2.3:a:zend:zendto:4.11-3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "97AAD0F3-C54A-4DFB-9C72-BACE392AB30B" }, { "criteria": "cpe:2.3:a:zend:zendto:4.11-4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "289CB602-06A2-4DF7-B9DC-BAFD7FC1FEA7" }, { "criteria": "cpe:2.3:a:zend:zendto:4.11-5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "81C93EF8-1189-49E9-AB98-58BA79E04F6E" }, { "criteria": "cpe:2.3:a:zend:zendto:4.11-7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "56B8A398-4A25-4C5B-95C8-7EE48FE72406" }, { "criteria": "cpe:2.3:a:zend:zendto:4.11-8:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5E93F880-9636-4D19-9EF9-D24EF990635D" }, { "criteria": "cpe:2.3:a:zend:zendto:4.11-9:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "674611D3-EAB1-45AC-BD2A-890BDE07A57E" }, { "criteria": "cpe:2.3:a:zend:zendto:4.11-10:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1620FA37-B729-43E5-B9C8-3D958EA09FC0" }, { "criteria": "cpe:2.3:a:zend:zendto:4.11-11:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0D94AE99-BBA4-47CA-973D-FB1DEE759ACB" } ], "operator": "OR" } ] } ]