Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-0298

Опубликовано: 05 мая 2015
Источник: redhat
CVSS2: 5.2
EPSS Низкий

Описание

Cross-site scripting (XSS) vulnerability in the manager web interface in mod_cluster before 1.3.2.Alpha1 allows remote attackers to inject arbitrary web script or HTML via a crafted MCMP message.

A flaw was found in the way the mod_cluster manager processed certain MCMP messages. An attacker with access to the network from which MCMP messages are allowed to be sent could use this flaw to execute arbitrary JavaScript code in the mod_cluster manager web interface.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss BRMS 5mod_clusterUnder investigation
Red Hat JBoss Data Grid 6mod_clusterUnder investigation
Red Hat JBoss Data Virtualization 6mod_clusterUnder investigation
Red Hat JBoss Enterprise Application Platform 5mod_clusterUnder investigation
Red Hat JBoss Enterprise Web Server 1mod_clusterUnder investigation
Red Hat JBoss Fuse Service Works 6mod_clusterUnder investigation
Red Hat JBoss Operations Network 3mod_clusterUnder investigation
Red Hat JBoss Portal 5mod_clusterUnder investigation
Red Hat JBoss Portal 6mod_clusterUnder investigation
Red Hat JBoss SOA Platform 5mod_clusterUnder investigation

Показывать по

Дополнительная информация

Статус:

Important
https://bugzilla.redhat.com/show_bug.cgi?id=1197769mod_cluster: JavaScript code injection is possible via MCMP mod_manager messages

EPSS

Процентиль: 55%
0.00322
Низкий

5.2 Medium

CVSS2

Связанные уязвимости

nvd
больше 10 лет назад

Cross-site scripting (XSS) vulnerability in the manager web interface in mod_cluster before 1.3.2.Alpha1 allows remote attackers to inject arbitrary web script or HTML via a crafted MCMP message.

debian
больше 10 лет назад

Cross-site scripting (XSS) vulnerability in the manager web interface ...

github
больше 3 лет назад

Cross-site scripting (XSS) vulnerability in the manager web interface in mod_cluster before 1.3.2.Alpha1 allows remote attackers to inject arbitrary web script or HTML via a crafted MCMP message.

EPSS

Процентиль: 55%
0.00322
Низкий

5.2 Medium

CVSS2

Уязвимость CVE-2015-0298