Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-10245

Опубликовано: 24 мая 2019
Источник: redhat
CVSS3: 6.1
EPSS Низкий

Описание

Insufficient sanitization of the query parameter in templates/html/search_opensearch.php could lead to reflected cross-site scripting or iframe injection.

Отчет

  • This issue did not affect the versions of doxygen as shipped with Red Hat Enterprise Linux 5, and 6 as they did not include the vulnerable file search_opensearch.php.
  • This issue did not affect the versions of doxygen as shipped with Red Hat Enterprise Linux 8 as they already include the patched code.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5doxygenNot affected
Red Hat Enterprise Linux 6doxygenNot affected
Red Hat Enterprise Linux 8doxygenNot affected
Red Hat Enterprise Linux 7doxygenFixedRHSA-2020:103431.03.2020

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=1714190doxygen: cross-site scripting in templates/html/search_opensearch.php

EPSS

Процентиль: 66%
0.00505
Низкий

6.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
ubuntu
больше 6 лет назад

Insufficient sanitization of the query parameter in templates/html/search_opensearch.php could lead to reflected cross-site scripting or iframe injection.

CVSS3: 6.1
nvd
больше 6 лет назад

Insufficient sanitization of the query parameter in templates/html/search_opensearch.php could lead to reflected cross-site scripting or iframe injection.

CVSS3: 6.1
debian
больше 6 лет назад

Insufficient sanitization of the query parameter in templates/html/sea ...

suse-cvrf
больше 6 лет назад

Security update for doxygen

suse-cvrf
больше 6 лет назад

Security update for doxygen

EPSS

Процентиль: 66%
0.00505
Низкий

6.1 Medium

CVSS3