CVE-2013-7351

unknown
Published — · Modified —
CVSS v3
CVSS v2
VIR risk

Description

Multiple cross-site scripting (XSS) vulnerabilities in index.php in Shaarli allow remote attackers to inject arbitrary web script or HTML via the URL to the (1) showRSS, (2) showATOM, or (3) showDailyRSS function; a (4) file name to the importFile function; or (5) vectors related to bookmarks.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2013-7351

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed0.0.41~beta~dfsg2-4
debian debiansidfixed0.0.41~beta~dfsg2-4
debian debiantrixiefixed0.0.41~beta~dfsg2-4

References

Verify integrity in audit chain (admin only). AS-IS.