Cross-site scripting (XSS) vulnerability in the skinning feature in SiteKiosk before 6.5.150 allows local users to bypass security protections and inject arbitrary web script or HTML via an ABOUT: URI, which is displayed in the title bar of the browser.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Sitekiosk | Sitekiosk | 4.9.11 (including) | 4.9.11 (including) |
Sitekiosk | Sitekiosk | 4.9.14 (including) | 4.9.14 (including) |
Sitekiosk | Sitekiosk | 4.96 (including) | 4.96 (including) |
Sitekiosk | Sitekiosk | 4.96.0 (including) | 4.96.0 (including) |
Sitekiosk | Sitekiosk | 4.96.3 (including) | 4.96.3 (including) |
Sitekiosk | Sitekiosk | 4.97.0 (including) | 4.97.0 (including) |
Sitekiosk | Sitekiosk | 5.0.19 (including) | 5.0.19 (including) |
Sitekiosk | Sitekiosk | 5.0.26 (including) | 5.0.26 (including) |
Sitekiosk | Sitekiosk | 5.0.32 (including) | 5.0.32 (including) |
Sitekiosk | Sitekiosk | 5.0.35 (including) | 5.0.35 (including) |
Sitekiosk | Sitekiosk | 5.0.36 (including) | 5.0.36 (including) |
Sitekiosk | Sitekiosk | 5.0.38 (including) | 5.0.38 (including) |
Sitekiosk | Sitekiosk | 5.0.41 (including) | 5.0.41 (including) |
Sitekiosk | Sitekiosk | 5.0.238 (including) | 5.0.238 (including) |
Sitekiosk | Sitekiosk | 5.0.248 (including) | 5.0.248 (including) |
Sitekiosk | Sitekiosk | 5.0.264 (including) | 5.0.264 (including) |
Sitekiosk | Sitekiosk | 5.5.34 (including) | 5.5.34 (including) |
Sitekiosk | Sitekiosk | 5.5.35 (including) | 5.5.35 (including) |
Sitekiosk | Sitekiosk | 5.5.36 (including) | 5.5.36 (including) |
Sitekiosk | Sitekiosk | 5.5.39 (including) | 5.5.39 (including) |
Sitekiosk | Sitekiosk | 5.5.45 (including) | 5.5.45 (including) |
Sitekiosk | Sitekiosk | 6.0.14 (including) | 6.0.14 (including) |
Sitekiosk | Sitekiosk | 6.0.98_final (including) | 6.0.98_final (including) |
Sitekiosk | Sitekiosk | 6.2.51 (including) | 6.2.51 (including) |
Sitekiosk | Sitekiosk | 6.5.149 (including) | 6.5.149 (including) |