Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2009-1175

Опубликовано: 31 мар. 2009
Источник: debian
EPSS Низкий

Описание

Cross-site scripting (XSS) vulnerability in apps/web/vs_diag.cgi in the DAAP extension in Banshee 1.4.2 allows remote attackers to inject arbitrary web script or HTML via the server parameter, which is not properly handled in an error message.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
bansheeunfixedpackage

Примечания

  • banshee is intented as a desktop music player with no serious

  • login credentials that an attacker could use remote

EPSS

Процентиль: 54%
0.00318
Низкий

Связанные уязвимости

ubuntu
больше 16 лет назад

Cross-site scripting (XSS) vulnerability in apps/web/vs_diag.cgi in the DAAP extension in Banshee 1.4.2 allows remote attackers to inject arbitrary web script or HTML via the server parameter, which is not properly handled in an error message.

nvd
больше 16 лет назад

Cross-site scripting (XSS) vulnerability in apps/web/vs_diag.cgi in the DAAP extension in Banshee 1.4.2 allows remote attackers to inject arbitrary web script or HTML via the server parameter, which is not properly handled in an error message.

github
больше 3 лет назад

Cross-site scripting (XSS) vulnerability in apps/web/vs_diag.cgi in the DAAP extension in Banshee 1.4.2 allows remote attackers to inject arbitrary web script or HTML via the server parameter, which is not properly handled in an error message.

EPSS

Процентиль: 54%
0.00318
Низкий