Описание
Cross-site scripting vulnerability in search.pl for Fluid Dynamics Search Engine (FDSE) before 2.0.0.0055 allows remote attackers to execute web script via the (1) Rank or (2) Match parameters.
Ссылки
- PatchVendor Advisory
- ExploitPatchVendor Advisory
- PatchVendor Advisory
- ExploitPatchVendor Advisory
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:a:zoltan_milosevic:fluid_dynamics_search_engine:2.0.0.0050:*:*:*:*:*:*:*
cpe:2.3:a:zoltan_milosevic:fluid_dynamics_search_engine:2.0.0.0051:*:*:*:*:*:*:*
cpe:2.3:a:zoltan_milosevic:fluid_dynamics_search_engine:2.0.0.0052:*:*:*:*:*:*:*
cpe:2.3:a:zoltan_milosevic:fluid_dynamics_search_engine:2.0.0.0053:*:*:*:*:*:*:*
cpe:2.3:a:zoltan_milosevic:fluid_dynamics_search_engine:2.0.0.0054:*:*:*:*:*:*:*
EPSS
Процентиль: 91%
0.0699
Низкий
7.5 High
CVSS2
Дефекты
NVD-CWE-Other
Связанные уязвимости
github
почти 4 года назад
Cross-site scripting vulnerability in search.pl for Fluid Dynamics Search Engine (FDSE) before 2.0.0.0055 allows remote attackers to execute web script via the (1) Rank or (2) Match parameters.
EPSS
Процентиль: 91%
0.0699
Низкий
7.5 High
CVSS2
Дефекты
NVD-CWE-Other