Description
Craft CMS before 2.6.2976 allows XSS attacks because an array returned by HttpRequestService::getSegments() and getActionSegments() need not be zero-based. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-8052.
Remediation
References
Related Vulnerabilities
WordPress Plugin wp superb Slideshow 'upload.php' Arbitrary File Upload (2.2)
GlassFish CVE-2012-3155 Vulnerability (CVE-2012-3155)
WordPress Plugin Fetch Tweets Cross-Site Scripting (2.6.4)
MySQL CVE-2013-0367 Vulnerability (CVE-2013-0367)
TYPO3 Cleartext Storage of Sensitive Information Vulnerability (CVE-2021-21339)