Vulnerabilities > CVE-2011-1952 - Resource Management Errors vulnerability in Postrev Post Revolution

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
PARTIAL
network
low complexity
postrev
CWE-399

Summary

common.php in Post Revolution before 0.8.0c-2 allows remote attackers to cause a denial of service (infinite loop) via malformed HTML markup, as demonstrated by an a< sequence.

Common Weakness Enumeration (CWE)

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/101893/postrevolution-xssxsrfdos.txt
idPACKETSTORM:101893
last seen2016-12-05
published2011-06-01
reporterJavier Bassi
sourcehttps://packetstormsecurity.com/files/101893/Post-Revolution-0.8.0c-XSS-XSRF-Denial-Of-Service.html
titlePost Revolution 0.8.0c XSS / XSRF / Denial Of Service