Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2013-1885

Опубликовано: 24 янв. 2014
Источник: nvd
CVSS2: 4.3
EPSS Низкий

Описание

Multiple cross-site scripting (XSS) vulnerabilities in the token processing system (pki-tps) in Red Hat Certificate System (RHCS) 8.1 and possibly Dogtag Certificate System 9 and 10 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) tus/ or (2) tus/tus/.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:redhat:certificate_system:8.1:*:*:*:*:*:*:*
cpe:2.3:a:redhat:dogtag_certificate_system:9.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:dogtag_certificate_system:10.0:*:*:*:*:*:*:*

EPSS

Процентиль: 47%
0.00238
Низкий

4.3 Medium

CVSS2

Дефекты

CWE-79

Связанные уязвимости

redhat
больше 12 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the token processing system (pki-tps) in Red Hat Certificate System (RHCS) 8.1 and possibly Dogtag Certificate System 9 and 10 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) tus/ or (2) tus/tus/.

github
больше 3 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the token processing system (pki-tps) in Red Hat Certificate System (RHCS) 8.1 and possibly Dogtag Certificate System 9 and 10 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) tus/ or (2) tus/tus/.

EPSS

Процентиль: 47%
0.00238
Низкий

4.3 Medium

CVSS2

Дефекты

CWE-79