Описание
Cross-site scripting (XSS) vulnerability in AWFFull before 3.7.4, when AllSearchStr (aka the All Search Terms report) is enabled, allows remote attackers to inject arbitrary web script or HTML via a search string.
Релиз | Статус | Примечание |
---|---|---|
dapper | DNE | |
devel | not-affected | |
edgy | DNE | |
feisty | ignored | end of life, was needed |
gutsy | not-affected | |
hardy | not-affected | |
upstream | needs-triage |
Показывать по
Ссылки на источники
4.3 Medium
CVSS2
Связанные уязвимости
Cross-site scripting (XSS) vulnerability in AWFFull before 3.7.4, when AllSearchStr (aka the All Search Terms report) is enabled, allows remote attackers to inject arbitrary web script or HTML via a search string.
Cross-site scripting (XSS) vulnerability in AWFFull before 3.7.4, when ...
Cross-site scripting (XSS) vulnerability in AWFFull before 3.7.4, when AllSearchStr (aka the All Search Terms report) is enabled, allows remote attackers to inject arbitrary web script or HTML via a search string.
4.3 Medium
CVSS2