Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2016-6127

Опубликовано: 03 июл. 2017
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 4.3
CVSS3: 6.1

Описание

Cross-site scripting (XSS) vulnerability in Request Tracker (RT) 4.x before 4.0.25, 4.2.x before 4.2.14, and 4.4.x before 4.4.2, when the AlwaysDownloadAttachments config setting is not in use, allows remote attackers to inject arbitrary web script or HTML via a file upload with an unspecified content type.

РелизСтатусПримечание
artful

not-affected

4.4.1-4
bionic

not-affected

4.4.1-4
cosmic

not-affected

4.4.1-4
devel

not-affected

4.4.1-4
disco

not-affected

4.4.1-4
eoan

not-affected

4.4.1-4
esm-apps-legacy/xenial

needed

esm-apps/bionic

not-affected

4.4.1-4
esm-apps/focal

not-affected

4.4.1-4
esm-apps/jammy

not-affected

4.4.1-4

Показывать по

Ссылки на источники

EPSS

Процентиль: 65%
0.01199
Низкий

4.3 Medium

CVSS2

6.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
nvd
около 9 лет назад

Cross-site scripting (XSS) vulnerability in Request Tracker (RT) 4.x before 4.0.25, 4.2.x before 4.2.14, and 4.4.x before 4.4.2, when the AlwaysDownloadAttachments config setting is not in use, allows remote attackers to inject arbitrary web script or HTML via a file upload with an unspecified content type.

CVSS3: 6.1
debian
около 9 лет назад

Cross-site scripting (XSS) vulnerability in Request Tracker (RT) 4.x b ...

CVSS3: 6.1
github
больше 4 лет назад

Cross-site scripting (XSS) vulnerability in Request Tracker (RT) 4.x before 4.0.25, 4.2.x before 4.2.14, and 4.4.x before 4.4.2, when the AlwaysDownloadAttachments config setting is not in use, allows remote attackers to inject arbitrary web script or HTML via a file upload with an unspecified content type.

EPSS

Процентиль: 65%
0.01199
Низкий

4.3 Medium

CVSS2

6.1 Medium

CVSS3