[Forgot Password]
Login  Register Subscribe

30480

 
 

423868

 
 

252212

 
 

909

 
 

196748

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2013-6837Date: (C)2013-12-27   (M)2024-02-22


Cross-site scripting (XSS) vulnerability in the setTimeout function in js/jquery.prettyPhoto.js in prettyPhoto 3.1.4 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted PATH_INTO to the default URI.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 4.3
Exploit Score: 8.6
Impact Score: 2.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: MEDIUM
Authentication: NONE
Confidentiality: NONE
Integrity: PARTIAL
Availability: NONE
  
Reference:
http://cxsecurity.com/issue/WLB-2013110149
http://themeforest.net/forums/thread/security-vulnerability-affecting-prettyphoto-jquery-script/181180
http://themeforest.net/item/udesign-responsive-wordpress-theme/253220
http://www.no-margin-for-errors.com/projects/prettyphoto-jquery-lightbox-clone/
http://www.perucrack.net/2014/07/haciendo-un-xss-en-plugin-prettyphoto.html
http://www.rafayhackingarticles.net/2013/05/kali-linux-dom-based-xss-writeup.html
https://github.com/Duncaen/prettyphoto/commit/3ef0ddfefebbcc6bbe9245f9cea87e26838e9bbc

CWE    1
CWE-79

© SecPod Technologies