CVE-2015-3397

Cross-site scripting (XSS) vulnerability in Yii Framework before 2.0.4 allows remote attackers to inject arbitrary web script or HTML via vectors related to JSON, arrays, and Internet Explorer 6 or 7.
Configurations

Configuration 1 (hide)

cpe:2.3:a:yiiframework:yiiframework:*:*:*:*:*:*:*:*

History

21 Nov 2024, 02:29

Type Values Removed Values Added
References () http://www.securityfocus.com/bid/74663 - () http://www.securityfocus.com/bid/74663 -
References () http://www.yiiframework.com/news/86/yii-2-0-4-is-released/ - Patch, Vendor Advisory () http://www.yiiframework.com/news/86/yii-2-0-4-is-released/ - Patch, Vendor Advisory
References () https://github.com/yiisoft/yii2/blob/2.0.4/framework/CHANGELOG.md - Patch () https://github.com/yiisoft/yii2/blob/2.0.4/framework/CHANGELOG.md - Patch

Information

Published : 2015-05-14 00:59

Updated : 2024-11-21 02:29


NVD link : CVE-2015-3397

Mitre link : CVE-2015-3397

CVE.ORG link : CVE-2015-3397


JSON object : View

Products Affected

yiiframework

  • yiiframework
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')