Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-5364

Опубликовано: 17 фев. 2017
Источник: debian
EPSS Низкий

Описание

Cross-site scripting (XSS) vulnerability in manage_custom_field_edit_page.php in MantisBT 1.2.19 and earlier allows remote attackers to inject arbitrary web script or HTML via the return parameter.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
mantisremovedpackage

Примечания

  • http://github.com/mantisbt/mantisbt/commit/5068df2d (1.2.x)

  • https://mantisbt.org/bugs/view.php?id=20956

EPSS

Процентиль: 53%
0.00297
Низкий

Связанные уязвимости

CVSS3: 6.1
ubuntu
почти 9 лет назад

Cross-site scripting (XSS) vulnerability in manage_custom_field_edit_page.php in MantisBT 1.2.19 and earlier allows remote attackers to inject arbitrary web script or HTML via the return parameter.

CVSS3: 6.1
nvd
почти 9 лет назад

Cross-site scripting (XSS) vulnerability in manage_custom_field_edit_page.php in MantisBT 1.2.19 and earlier allows remote attackers to inject arbitrary web script or HTML via the return parameter.

CVSS3: 6.1
github
больше 3 лет назад

Cross-site scripting (XSS) vulnerability in manage_custom_field_edit_page.php in MantisBT 1.2.19 and earlier allows remote attackers to inject arbitrary web script or HTML via the return parameter.

EPSS

Процентиль: 53%
0.00297
Низкий