Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2015-5216

Опубликовано: 17 фев. 2020
Источник: nvd
CVSS3: 6.1
CVSS2: 4.3
EPSS Низкий

Описание

The Identity Provider (IdP) server in Ipsilon 0.1.0 before 1.0.1 does not properly escape certain characters in a Python exception-message template, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via an HTTP response.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:ipsilon-project:ipsilon:*:*:*:*:*:*:*:*
Версия от 0.1.0 (включая) до 1.0.1 (исключая)

EPSS

Процентиль: 69%
0.0059
Низкий

6.1 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-79

Связанные уязвимости

redhat
больше 10 лет назад

The Identity Provider (IdP) server in Ipsilon 0.1.0 before 1.0.1 does not properly escape certain characters in a Python exception-message template, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via an HTTP response.

CVSS3: 6.1
debian
почти 6 лет назад

The Identity Provider (IdP) server in Ipsilon 0.1.0 before 1.0.1 does ...

CVSS3: 6.1
github
больше 3 лет назад

The Identity Provider (IdP) server in Ipsilon 0.1.0 before 1.0.1 does not properly escape certain characters in a Python exception-message template, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via an HTTP response.

EPSS

Процентиль: 69%
0.0059
Низкий

6.1 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-79