Multiple cross-site scripting (XSS) vulnerabilities in ImpressCMS 1.2.x before 1.2.7 Final and 1.3.x before 1.3.1 Final allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) notifications.php, (2) modules/system/admin/images/browser.php, and (3) modules/content/admin/content.php.
| Software | From | Fixed in |
|---|---|---|
impresscms / impresscms
|
1.2.6-final | 1.2.6-final.x |
impresscms / impresscms
|
1.2.3-rc2 | 1.2.3-rc2.x |
impresscms / impresscms
|
1.2.5-final | 1.2.5-final.x |
impresscms / impresscms
|
1.2.3-final | 1.2.3-final.x |
impresscms / impresscms
|
1.2-final | 1.2-final.x |
impresscms / impresscms
|
1.2.3-rc1 | 1.2.3-rc1.x |
impresscms / impresscms
|
1.3 | 1.3.x |
impresscms / impresscms
|
1.2.1-final | 1.2.1-final.x |
impresscms / impresscms
|
1.2.1-beta | 1.2.1-beta.x |
impresscms / impresscms
|
1.2.3-beta | 1.2.3-beta.x |
impresscms / impresscms
|
1.2-rc1 | 1.2-rc1.x |
impresscms / impresscms
|
1.2-alpha1 | 1.2-alpha1.x |
impresscms / impresscms
|
1.2.1-rc1 | 1.2.1-rc1.x |
impresscms / impresscms
|
1.2-rc2 | 1.2-rc2.x |
impresscms / impresscms
|
1.2-alpha2 | 1.2-alpha2.x |
impresscms / impresscms
|
1.2-beta | 1.2-beta.x |
impresscms / impresscms
|
1.2.4-final | 1.2.4-final.x |