← Back

CVE-2013-0805

nvd nist
Published: Mar 20, 2014Modified: May 6, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:N/I:P/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

Multiple cross-site scripting (XSS) vulnerabilities in the search feature in iTop (aka IT Operations Portal) 2.0, 1.2.1, 1.2, and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) text parameter to pages/UI.php or (2) expression parameter to pages/run_query.php. NOTE: some of these details are obtained from third party information.

Affected (24)

Products: Combodo: Itop
1 product
Itop
Configuration A
24 vulnerable
Vulnerable SoftwareAffected Versions
Combodo
Up to 2.0
Version 0.7.1
Version 0.7.2
Version 0.8.1.3
Version 0.8
Version 0.9.1
Version 0.9
Version 0.9 beta
Version 1.0.1
Version 1.0.2
Version 1.0.2 beta
Version 1.0
Version 1.0 beta
Version 1.1.181
Version 1.1
Version 1.1 beta
Version 1.2.0
Version 1.2.0 rc282
Version 1.2.1
Version 1.2.1 beta
Version 1.2
Version 1.2 beta
Version 2.0 beta2
Version 2.0 beta

References (14)

Source: cve@mitre.org
Source: cve@mitre.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.