Описание
Cross-site scripting (XSS) vulnerability in Sawmill 7.0.0 through 7.1.13 allows remote attackers to inject arbitrary web script or HTML via the query string in an HTTP GET request.
Ссылки
- ExploitVendor Advisory
- ExploitVendor Advisory
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:a:sawmill:sawmill:7.0.0:*:*:*:*:*:*:*
cpe:2.3:a:sawmill:sawmill:7.0.1:*:*:*:*:*:*:*
cpe:2.3:a:sawmill:sawmill:7.0.2:*:*:*:*:*:*:*
cpe:2.3:a:sawmill:sawmill:7.0.3:*:*:*:*:*:*:*
cpe:2.3:a:sawmill:sawmill:7.0.4:*:*:*:*:*:*:*
cpe:2.3:a:sawmill:sawmill:7.0.5:*:*:*:*:*:*:*
cpe:2.3:a:sawmill:sawmill:7.0.6:*:*:*:*:*:*:*
cpe:2.3:a:sawmill:sawmill:7.0.7:*:*:*:*:*:*:*
cpe:2.3:a:sawmill:sawmill:7.0.8:*:*:*:*:*:*:*
cpe:2.3:a:sawmill:sawmill:7.0.9:*:*:*:*:*:*:*
cpe:2.3:a:sawmill:sawmill:7.0.10:*:*:*:*:*:*:*
cpe:2.3:a:sawmill:sawmill:7.0.10a:*:*:*:*:*:*:*
cpe:2.3:a:sawmill:sawmill:7.0.10b:*:*:*:*:*:*:*
cpe:2.3:a:sawmill:sawmill:7.0.10c:*:*:*:*:*:*:*
cpe:2.3:a:sawmill:sawmill:7.0.10d:*:*:*:*:*:*:*
cpe:2.3:a:sawmill:sawmill:7.0.10e:*:*:*:*:*:*:*
cpe:2.3:a:sawmill:sawmill:7.0.10f:*:*:*:*:*:*:*
cpe:2.3:a:sawmill:sawmill:7.0.10g:*:*:*:*:*:*:*
cpe:2.3:a:sawmill:sawmill:7.0.10h:*:*:*:*:*:*:*
cpe:2.3:a:sawmill:sawmill:7.0.10i:*:*:*:*:*:*:*
cpe:2.3:a:sawmill:sawmill:7.0.10j:*:*:*:*:*:*:*
cpe:2.3:a:sawmill:sawmill:7.0.10k:*:*:*:*:*:*:*
cpe:2.3:a:sawmill:sawmill:7.1:*:*:*:*:*:*:*
cpe:2.3:a:sawmill:sawmill:7.1.1:*:*:*:*:*:*:*
cpe:2.3:a:sawmill:sawmill:7.1.2:*:*:*:*:*:*:*
cpe:2.3:a:sawmill:sawmill:7.1.3:*:*:*:*:*:*:*
cpe:2.3:a:sawmill:sawmill:7.1.4:*:*:*:*:*:*:*
cpe:2.3:a:sawmill:sawmill:7.1.5:*:*:*:*:*:*:*
cpe:2.3:a:sawmill:sawmill:7.1.6:*:*:*:*:*:*:*
cpe:2.3:a:sawmill:sawmill:7.1.7:*:*:*:*:*:*:*
cpe:2.3:a:sawmill:sawmill:7.1.8:*:*:*:*:*:*:*
cpe:2.3:a:sawmill:sawmill:7.1.9:*:*:*:*:*:*:*
cpe:2.3:a:sawmill:sawmill:7.1.10:*:*:*:*:*:*:*
cpe:2.3:a:sawmill:sawmill:7.1.11:*:*:*:*:*:*:*
cpe:2.3:a:sawmill:sawmill:7.1.12:*:*:*:*:*:*:*
cpe:2.3:a:sawmill:sawmill:7.1.13:*:*:*:*:*:*:*
cpe:2.3:a:sawmill:sawmill:7.1.14:*:*:*:*:*:*:*
EPSS
Процентиль: 70%
0.00622
Низкий
4.3 Medium
CVSS2
Дефекты
NVD-CWE-Other
Связанные уязвимости
github
почти 4 года назад
Cross-site scripting (XSS) vulnerability in Sawmill 7.0.0 through 7.1.13 allows remote attackers to inject arbitrary web script or HTML via the query string in an HTTP GET request.
EPSS
Процентиль: 70%
0.00622
Низкий
4.3 Medium
CVSS2
Дефекты
NVD-CWE-Other