Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-1000998

Опубликовано: 04 фев. 2019
Источник: debian
EPSS Низкий

Описание

FreeBSD CVSweb version 2.x contains a Cross Site Scripting (XSS) vulnerability in all pages that can result in limited impact--CVSweb is anonymous & read-only. It might impact other sites on same domain. This attack appears to be exploitable via victim must load specially crafted url. This vulnerability appears to have been fixed in 3.x.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
cvswebfixed3:3.0.0-1package

Примечания

  • https://www.kvakil.me/posts/cvsweb/

EPSS

Процентиль: 49%
0.00262
Низкий

Связанные уязвимости

CVSS3: 6.1
ubuntu
около 7 лет назад

FreeBSD CVSweb version 2.x contains a Cross Site Scripting (XSS) vulnerability in all pages that can result in limited impact--CVSweb is anonymous & read-only. It might impact other sites on same domain. This attack appears to be exploitable via victim must load specially crafted url. This vulnerability appears to have been fixed in 3.x.

CVSS3: 6.1
nvd
около 7 лет назад

FreeBSD CVSweb version 2.x contains a Cross Site Scripting (XSS) vulnerability in all pages that can result in limited impact--CVSweb is anonymous & read-only. It might impact other sites on same domain. This attack appears to be exploitable via victim must load specially crafted url. This vulnerability appears to have been fixed in 3.x.

CVSS3: 6.1
github
больше 3 лет назад

FreeBSD CVSweb version 2.x contains a Cross Site Scripting (XSS) vulnerability in all pages that can result in limited impact--CVSweb is anonymous & read-only. It might impact other sites on same domain. This attack appears to be exploitable via victim must load specially crafted url. This vulnerability appears to have been fixed in 3.x.

EPSS

Процентиль: 49%
0.00262
Низкий