Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2013-1808

Опубликовано: 18 фев. 2013
Источник: redhat
CVSS2: 4.3
EPSS Низкий

Описание

Cross-site scripting (XSS) vulnerability in ZeroClipboard.swf and ZeroClipboard10.swf in ZeroClipboard before 1.0.8, as used in em-shorty, RepRapCalculator, Fulcrum, Django, aCMS, and other products, allows remote attackers to inject arbitrary web script or HTML via the id parameter. NOTE: this is might be the same vulnerability as CVE-2013-1463. If so, it is likely that CVE-2013-1463 will be REJECTed.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Subscription Asset ManagerDjangoNot affected
RHEL 6 Version of OpenShift Enterprise 1.2atlasFixedRHEA-2013:103209.07.2013
RHEL 6 Version of OpenShift Enterprise 1.2facterFixedRHEA-2013:103209.07.2013
RHEL 6 Version of OpenShift Enterprise 1.2gdFixedRHEA-2013:103209.07.2013
RHEL 6 Version of OpenShift Enterprise 1.2gdbmFixedRHEA-2013:103209.07.2013
RHEL 6 Version of OpenShift Enterprise 1.2geosFixedRHEA-2013:103209.07.2013
RHEL 6 Version of OpenShift Enterprise 1.2ghostscriptFixedRHEA-2013:103209.07.2013
RHEL 6 Version of OpenShift Enterprise 1.2haproxyFixedRHEA-2013:103209.07.2013
RHEL 6 Version of OpenShift Enterprise 1.2ImageMagickFixedRHEA-2013:103209.07.2013
RHEL 6 Version of OpenShift Enterprise 1.2jasperFixedRHEA-2013:103209.07.2013

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=918054stapler-adjunct-zeroclipboard: XSS via copying XSS payload into buffer

EPSS

Процентиль: 82%
0.01651
Низкий

4.3 Medium

CVSS2

Связанные уязвимости

nvd
почти 13 лет назад

Cross-site scripting (XSS) vulnerability in ZeroClipboard.swf and ZeroClipboard10.swf in ZeroClipboard before 1.0.8, as used in em-shorty, RepRapCalculator, Fulcrum, Django, aCMS, and other products, allows remote attackers to inject arbitrary web script or HTML via the id parameter. NOTE: this is might be the same vulnerability as CVE-2013-1463. If so, it is likely that CVE-2013-1463 will be REJECTed.

debian
почти 13 лет назад

Cross-site scripting (XSS) vulnerability in ZeroClipboard.swf and Zero ...

github
больше 3 лет назад

Cross-site scripting (XSS) vulnerability in ZeroClipboard.swf and ZeroClipboard10.swf in ZeroClipboard before 1.0.8, as used in em-shorty, RepRapCalculator, Fulcrum, Django, aCMS, and other products, allows remote attackers to inject arbitrary web script or HTML via the id parameter. NOTE: this is might be the same vulnerability as CVE-2013-1463. If so, it is likely that CVE-2013-1463 will be REJECTed.

EPSS

Процентиль: 82%
0.01651
Низкий

4.3 Medium

CVSS2