icon

We found results for “

CVE-2016-10510

Good to know:

icon

Date: August 31, 2017

Cross-site scripting (XSS) vulnerability in the Security component of Kohana before 3.3.6 allows remote attackers to inject arbitrary web script or HTML by bypassing the strip_image_tags protection mechanism in system/classes/Kohana/Security.php.

Language: PHP

Severity Score

Severity Score

Weakness Type (CWE)

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CWE-79

Top Fix

icon

Upgrade Version

Upgrade to version openbuildings/kohana-test-bootstrap - 0.2.0;app-skeleton/core - no_fix;app-skeleton/core - beta1;app-skeleton/core - v3.2.0-RC1;doorframework/core - no_fix;and/kohana-core - v3.2.0-RC1;and/kohana-core - beta1;and/kohana-core - no_fix;openbuildings/kohana-test-bootsrap - 0.2.0;kohana/core - v3.3.3;kohana/core - v3.2.0-RC1;kohana/core - v3.3.6;kohana/core - dev-3.4/feature/more-log-filters

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): LOW
Privileges Required (PR): NONE
User Interaction (UI): REQUIRED
Scope (S): CHANGED
Confidentiality (C): LOW
Integrity (I): LOW
Availability (A): NONE

CVSS v2

Base Score:
Access Vector (AV): NETWORK
Access Complexity (AC): MEDIUM
Authentication (AU): NONE
Confidentiality (C): NONE
Integrity (I): PARTIAL
Availability (A): NONE
Additional information:

Do you need more information?

Contact Us