Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2016-10516

Опубликовано: 23 окт. 2017
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 4.3
CVSS3: 6.1

Описание

Cross-site scripting (XSS) vulnerability in the render_full function in debug/tbtools.py in the debugger in Pallets Werkzeug before 0.11.11 (as used in Pallets Flask and other products) allows remote attackers to inject arbitrary web script or HTML via a field that contains an exception message.

РелизСтатусПримечание
artful

not-affected

0.12.2+dfsg1-2
devel

not-affected

0.12.2+dfsg1-2
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was released [0.9.4+dfsg-1.1ubuntu2.1]]
esm-infra/xenial

released

0.10.4+dfsg1-1ubuntu1.1
precise/esm

DNE

trusty

released

0.9.4+dfsg-1.1ubuntu2.1
trusty/esm

DNE

trusty was released [0.9.4+dfsg-1.1ubuntu2.1]
upstream

released

0.11.11
xenial

released

0.10.4+dfsg1-1ubuntu1.1
zesty

not-affected

0.11.15+dfsg1-1

Показывать по

EPSS

Процентиль: 54%
0.00314
Низкий

4.3 Medium

CVSS2

6.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.1
redhat
больше 8 лет назад

Cross-site scripting (XSS) vulnerability in the render_full function in debug/tbtools.py in the debugger in Pallets Werkzeug before 0.11.11 (as used in Pallets Flask and other products) allows remote attackers to inject arbitrary web script or HTML via a field that contains an exception message.

CVSS3: 6.1
nvd
больше 8 лет назад

Cross-site scripting (XSS) vulnerability in the render_full function in debug/tbtools.py in the debugger in Pallets Werkzeug before 0.11.11 (as used in Pallets Flask and other products) allows remote attackers to inject arbitrary web script or HTML via a field that contains an exception message.

CVSS3: 6.1
debian
больше 8 лет назад

Cross-site scripting (XSS) vulnerability in the render_full function i ...

CVSS3: 6.1
github
больше 3 лет назад

Pallets Werkzeug cross-site scripting vulnerability

EPSS

Процентиль: 54%
0.00314
Низкий

4.3 Medium

CVSS2

6.1 Medium

CVSS3