Description
In Joomla! 3.2.0 through 3.6.5 (fixed in 3.7.0), inadequate escaping of file and folder names leads to XSS vulnerabilities in the template manager component.
Remediation
References
Related Vulnerabilities
Oracle JRE CVE-2013-2412 Vulnerability (CVE-2013-2412)
WordPress 4.1.x Possible SQL Injection Vulnerability (4.1 - 4.1.19)
WordPress Plugin Quotes and Tips by BestWebSoft Cross-Site Scripting (1.32)
WordPress Plugin ELEX WooCommerce Google Shopping (Google Product Feed) Cross-Site Scripting (1.2.3)
WordPress Plugin Claptastic Clap! Button Multiple Cross-Site Scripting Vulnerabilities (1.3)