Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2019-7337

Опубликовано: 04 фев. 2019
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 3.5
CVSS3: 4.8

Описание

Reflected Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3 as the view 'events' (events.php) insecurely displays the limit parameter value, without applying any proper output filtration. This issue exists because of the function sortHeader() in functions.php, which insecurely returns the value of the limit query string parameter without applying any filtration.

РелизСтатусПримечание
bionic

DNE

cosmic

ignored

end of life
devel

needed

disco

ignored

end of life
eoan

ignored

end of life
esm-apps/focal

needed

esm-apps/jammy

needed

esm-apps/noble

needed

esm-apps/xenial

needed

esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was needs-triage]

Показывать по

EPSS

Процентиль: 55%
0.00321
Низкий

3.5 Low

CVSS2

4.8 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.8
nvd
около 7 лет назад

Reflected Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3 as the view 'events' (events.php) insecurely displays the limit parameter value, without applying any proper output filtration. This issue exists because of the function sortHeader() in functions.php, which insecurely returns the value of the limit query string parameter without applying any filtration.

CVSS3: 4.8
debian
около 7 лет назад

Reflected Cross Site Scripting (XSS) exists in ZoneMinder through 1.32 ...

CVSS3: 4.8
github
больше 3 лет назад

Reflected Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3 as the view 'events' (events.php) insecurely displays the limit parameter value, without applying any proper output filtration. This issue exists because of the function sortHeader() in functions.php, which insecurely returns the value of the limit query string parameter without applying any filtration.

EPSS

Процентиль: 55%
0.00321
Низкий

3.5 Low

CVSS2

4.8 Medium

CVSS3