Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-0149

Опубликовано: 01 мая 2014
Источник: redhat
CVSS2: 4.3

Описание

Multiple cross-site scripting (XSS) vulnerabilities in Red Hat JBoss Web Framework Kit 2.5.0 allow remote attackers to inject arbitrary web script or HTML via a (1) parameter or (2) id name.

Отчет

Red Hat JBoss Enterprise Application Platform 4 and 5; Red Hat JBoss Enterprise Portal Platform 5; and Red Hat JBoss Enterprise SOA Platform 4 and 5 are now in Phase 3, Extended Life Support, of their respective life cycles. This issue has been rated as having Moderate security impact and is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat JBoss Middleware and Red Hat JBoss Operations Network Product Update and Support Policy: https://access.redhat.com/support/policy/updates/jboss_notes/

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss Enterprise Application Platform 4seam-remotingWill not fix
Red Hat JBoss Enterprise Application Platform 5seam-remotingWill not fix
Red Hat JBoss Enterprise Web Server 1ewp-5Will not fix
Red Hat JBoss Enterprise Web Server 1othersNot affected
Red Hat JBoss Portal 5seam-remotingWill not fix
Red Hat JBoss SOA Platform 4seam-remotingWill not fix
Red Hat JBoss SOA Platform 5seam-remotingWill not fix
Red Hat JBoss Web Framework Kit 2.5FixedRHSA-2014:046201.05.2014

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79

4.3 Medium

CVSS2

Связанные уязвимости

nvd
почти 12 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Red Hat JBoss Web Framework Kit 2.5.0 allow remote attackers to inject arbitrary web script or HTML via a (1) parameter or (2) id name.

github
больше 3 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Red Hat JBoss Web Framework Kit 2.5.0 allow remote attackers to inject arbitrary web script or HTML via a (1) parameter or (2) id name.

4.3 Medium

CVSS2