Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2007-5496

Опубликовано: 23 мая 2008
Источник: nvd
CVSS2: 1.9
EPSS Низкий

Описание

Cross-site scripting (XSS) vulnerability in setroubleshoot 2.0.5 allows local users to inject arbitrary web script or HTML via a crafted (1) file or (2) process name, which triggers an Access Vector Cache (AVC) log entry in a log file used during composition of HTML documents for sealert.

Уязвимые конфигурации

Конфигурация 1

Одновременно

Одно из

cpe:2.3:o:redhat:enterprise_linux:5.0:*:server:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_desktop:5:*:client:*:*:*:*:*
cpe:2.3:a:selinux:setroubleshoot:2.0.5:*:*:*:*:*:*:*

EPSS

Процентиль: 22%
0.00069
Низкий

1.9 Low

CVSS2

Дефекты

CWE-79

Связанные уязвимости

redhat
около 17 лет назад

Cross-site scripting (XSS) vulnerability in setroubleshoot 2.0.5 allows local users to inject arbitrary web script or HTML via a crafted (1) file or (2) process name, which triggers an Access Vector Cache (AVC) log entry in a log file used during composition of HTML documents for sealert.

github
около 3 лет назад

Cross-site scripting (XSS) vulnerability in setroubleshoot 2.0.5 allows local users to inject arbitrary web script or HTML via a crafted (1) file or (2) process name, which triggers an Access Vector Cache (AVC) log entry in a log file used during composition of HTML documents for sealert.

oracle-oval
около 17 лет назад

ELSA-2008-0061: setroubleshoot security and bug fix update (MODERATE)

EPSS

Процентиль: 22%
0.00069
Низкий

1.9 Low

CVSS2

Дефекты

CWE-79