Описание
The CGI framework in Kaya 0.4.0 allows remote attackers to inject arbitrary HTTP headers and conduct cross-site scripting (XSS) attacks via unspecified vectors.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| kaya | fixed | 0.4.2-1 | package | |
| kaya | no-dsa | etch | package |
Примечания
the fix checks with a regex for malicious characters in the HTTP header, see CGI.k changes
EPSS
Процентиль: 62%
0.0105
Низкий
Связанные уязвимости
ubuntu
больше 17 лет назад
The CGI framework in Kaya 0.4.0 allows remote attackers to inject arbitrary HTTP headers and conduct cross-site scripting (XSS) attacks via unspecified vectors.
nvd
больше 17 лет назад
The CGI framework in Kaya 0.4.0 allows remote attackers to inject arbitrary HTTP headers and conduct cross-site scripting (XSS) attacks via unspecified vectors.
github
больше 4 лет назад
The CGI framework in Kaya 0.4.0 allows remote attackers to inject arbitrary HTTP headers and conduct cross-site scripting (XSS) attacks via unspecified vectors.
EPSS
Процентиль: 62%
0.0105
Низкий