Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2014-2856

Опубликовано: 18 апр. 2014
Источник: debian
EPSS Низкий

Описание

Cross-site scripting (XSS) vulnerability in scheduler/client.c in Common Unix Printing System (CUPS) before 1.7.2 allows remote attackers to inject arbitrary web script or HTML via the URL path, related to the is_path_absolute function.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
cupsfixed1.7.2-1package
cupsfixed1.4.4-7+squeeze5squeezepackage
cupsfixed1.5.3-5+deb7u2wheezypackage

Примечания

  • http://www.cups.org/str.php?L4356

EPSS

Процентиль: 76%
0.01035
Низкий

Связанные уязвимости

ubuntu
больше 11 лет назад

Cross-site scripting (XSS) vulnerability in scheduler/client.c in Common Unix Printing System (CUPS) before 1.7.2 allows remote attackers to inject arbitrary web script or HTML via the URL path, related to the is_path_absolute function.

redhat
больше 11 лет назад

Cross-site scripting (XSS) vulnerability in scheduler/client.c in Common Unix Printing System (CUPS) before 1.7.2 allows remote attackers to inject arbitrary web script or HTML via the URL path, related to the is_path_absolute function.

nvd
больше 11 лет назад

Cross-site scripting (XSS) vulnerability in scheduler/client.c in Common Unix Printing System (CUPS) before 1.7.2 allows remote attackers to inject arbitrary web script or HTML via the URL path, related to the is_path_absolute function.

github
больше 3 лет назад

Cross-site scripting (XSS) vulnerability in scheduler/client.c in Common Unix Printing System (CUPS) before 1.7.2 allows remote attackers to inject arbitrary web script or HTML via the URL path, related to the is_path_absolute function.

oracle-oval
почти 11 лет назад

ELSA-2014-1388: cups security and bug fix update (MODERATE)

EPSS

Процентиль: 76%
0.01035
Низкий