Cross-site scripting (XSS) vulnerability in system/modules/comments/Comments.php in Contao CMS 2.9.2, and possibly other versions before 2.9.3, allows remote attackers to inject arbitrary web script or HTML via the HTTP X_FORWARDED_FOR header, which is stored by system/libraries/Environment.php but not properly handled by a comments action to main.php.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2011-01-20T18:00:00

Updated: 2024-08-06T21:58:24.570Z

Reserved: 2011-01-20T00:00:00

Link: CVE-2011-0508

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2011-01-20T19:00:10.817

Modified: 2018-10-09T19:29:11.373

Link: CVE-2011-0508

cve-icon Redhat

No data.