Описание
Cross-site scripting (XSS) vulnerability in the chg_passwd function in web/swat.c in the Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.10 allows remote authenticated administrators to inject arbitrary web script or HTML via the username parameter to the passwd program (aka the user field to the Change Password page).
Ссылки
- Third Party Advisory
- Broken Link
- Vendor Advisory
- Not ApplicableVendor Advisory
- Not ApplicableThird Party Advisory
- Not ApplicableThird Party Advisory
- Broken LinkThird Party AdvisoryVDB Entry
- Third Party Advisory
- Third Party Advisory
- Broken LinkThird Party Advisory
- Broken LinkThird Party Advisory
- Broken Link
- Vendor Advisory
- Third Party AdvisoryVDB Entry
- Issue TrackingPatch
- Issue TrackingPatch
- Third Party AdvisoryVDB Entry
- Third Party Advisory
- Broken Link
- Vendor Advisory
Уязвимые конфигурации
Одно из
Одно из
Одно из
EPSS
2.6 Low
CVSS2
Дефекты
Связанные уязвимости
Cross-site scripting (XSS) vulnerability in the chg_passwd function in web/swat.c in the Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.10 allows remote authenticated administrators to inject arbitrary web script or HTML via the username parameter to the passwd program (aka the user field to the Change Password page).
Cross-site scripting (XSS) vulnerability in the chg_passwd function in web/swat.c in the Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.10 allows remote authenticated administrators to inject arbitrary web script or HTML via the username parameter to the passwd program (aka the user field to the Change Password page).
Cross-site scripting (XSS) vulnerability in the chg_passwd function in ...
Cross-site scripting (XSS) vulnerability in the chg_passwd function in web/swat.c in the Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.10 allows remote authenticated administrators to inject arbitrary web script or HTML via the username parameter to the passwd program (aka the user field to the Change Password page).
EPSS
2.6 Low
CVSS2