Eva.Web.Index.PHP3.File.Inclusion

description-logoDescription

This indicates a vulnerability in EVA-Web. It allows remote attackers to conduct cross-site scripting attacks via invalid "perso" or "aide" parameters .

affected-products-logoAffected Products

SPIP-Education EVA-Web 2.1.2
SPIP-Education EVA-Web 2.2
SPIP-Education EVA-Web 2.1
SPIP-Education EVA-Web 2.0

Impact logoImpact

Cross site scripting.

recomended-action-logoRecommended Actions

Currently we are not aware of any official fix for this issue.

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)