"value":"Multiple cross-site scripting (XSS) vulnerabilities in Ripe Website Manager 0.8.9 and earlier allow remote authenticated users to inject arbitrary web script or HTML via one or more of the following vectors: the (1) id parameter to (a) pages/delete_page.php, (b) navigation/delete_menu.php, and (c) navigation/delete_item.php in admin/; the (2) menu_id, (3) name, (3) page_id, and (4) url parameters in (d) admin/navigation/do_new_item.php; the (5) new_menuname parameter in (e) admin/navigation/do_new_nav.php; and (6) area1, name, and url parameters to (f) admin/pages/do_new_page.php, probably involving the Title or textarea field as reachable through admin/pages/new_page.php. NOTE: the original disclosure does not precisely state which vectors are associated with SQL injection versus XSS."
},
{
"lang":"es",
"value":"M\u00faltiples vulnerabilidades de inyecci\u00f3n SQL en Ripe Website Manager 0.8.9 y versiones anteriores permite a usuarios remotos autenticados inyectar scripts web o HTML de su elecci\u00f3n mediante uno o mas de los siguientes vectores: (1) par\u00e1metro id en (a) pages/delete_page.php, (b) navigation/delete_menu.php, y (c) navigation/delete_item.php en admin/; par\u00e1metros (2) menu_id, (3) name, (3) page_id, y (4) url en (d) admin/navigation/do_new_item.php; par\u00e1metro (5) new_menuname en (e) admin/navigation/do_new_nav.php; y (6) par\u00e1metro2 area1, name, y url en (f) admin/pages/do_new_page.php, probablemente involucrando el campo Title \u00f3 textarea como alcanzable a trav\u00e9s de admin/pages/new_page.php.\r\nNOTA: La informaci\u00f3n original no se\u00f1ala con precisi\u00f3n qu\u00e9 vectores se asocian a una iyecci\u00f3n SQL frente a XSS."