Описание
Cross-site scripting (XSS) vulnerability in scheduler/client.c in Common Unix Printing System (CUPS) before 1.7.2 allows remote attackers to inject arbitrary web script or HTML via the URL path, related to the is_path_absolute function.
Релиз | Статус | Примечание |
---|---|---|
devel | released | 1.7.2-0ubuntu1 |
esm-infra-legacy/trusty | DNE | trusty/esm was DNE [trusty was released [1.7.2-0ubuntu1]] |
lucid | released | 1.4.3-1ubuntu1.11 |
precise | released | 1.5.3-0ubuntu8.2 |
quantal | released | 1.6.1-0ubuntu11.6 |
saucy | released | 1.7.0~rc1-0ubuntu5.3 |
trusty | released | 1.7.2-0ubuntu1 |
trusty/esm | DNE | trusty was released [1.7.2-0ubuntu1] |
upstream | released | 1.7.2 |
Показывать по
EPSS
4.3 Medium
CVSS2
Связанные уязвимости
Cross-site scripting (XSS) vulnerability in scheduler/client.c in Common Unix Printing System (CUPS) before 1.7.2 allows remote attackers to inject arbitrary web script or HTML via the URL path, related to the is_path_absolute function.
Cross-site scripting (XSS) vulnerability in scheduler/client.c in Common Unix Printing System (CUPS) before 1.7.2 allows remote attackers to inject arbitrary web script or HTML via the URL path, related to the is_path_absolute function.
Cross-site scripting (XSS) vulnerability in scheduler/client.c in Comm ...
Cross-site scripting (XSS) vulnerability in scheduler/client.c in Common Unix Printing System (CUPS) before 1.7.2 allows remote attackers to inject arbitrary web script or HTML via the URL path, related to the is_path_absolute function.
ELSA-2014-1388: cups security and bug fix update (MODERATE)
EPSS
4.3 Medium
CVSS2