Описание
Cross-site scripting (XSS) vulnerability in scheduler/client.c in Common Unix Printing System (CUPS) before 1.7.2 allows remote attackers to inject arbitrary web script or HTML via the URL path, related to the is_path_absolute function.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | released | 1.7.2-0ubuntu1 |
| esm-infra-legacy/trusty | DNE | trusty/esm was DNE [trusty was released [1.7.2-0ubuntu1]] |
| lucid | released | 1.4.3-1ubuntu1.11 |
| precise | released | 1.5.3-0ubuntu8.2 |
| quantal | released | 1.6.1-0ubuntu11.6 |
| saucy | released | 1.7.0~rc1-0ubuntu5.3 |
| trusty | released | 1.7.2-0ubuntu1 |
| trusty/esm | DNE | trusty was released [1.7.2-0ubuntu1] |
| upstream | released | 1.7.2 |
Показывать по
EPSS
4.3 Medium
CVSS2
Связанные уязвимости
Cross-site scripting (XSS) vulnerability in scheduler/client.c in Common Unix Printing System (CUPS) before 1.7.2 allows remote attackers to inject arbitrary web script or HTML via the URL path, related to the is_path_absolute function.
Cross-site scripting (XSS) vulnerability in scheduler/client.c in Common Unix Printing System (CUPS) before 1.7.2 allows remote attackers to inject arbitrary web script or HTML via the URL path, related to the is_path_absolute function.
Cross-site scripting (XSS) vulnerability in scheduler/client.c in Comm ...
Cross-site scripting (XSS) vulnerability in scheduler/client.c in Common Unix Printing System (CUPS) before 1.7.2 allows remote attackers to inject arbitrary web script or HTML via the URL path, related to the is_path_absolute function.
ELSA-2014-1388: cups security and bug fix update (MODERATE)
EPSS
4.3 Medium
CVSS2