Логотип exploitDog
bind:CVE-2017-12439
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2017-12439

Количество 2

Количество 2

nvd логотип

CVE-2017-12439

больше 8 лет назад

SocuSoft Flash Slideshow Maker Professional through v5.20, when the advanced configuration is used, has an xml_path HTTP parameter that trusts user-supplied input, in conjunction with an unsafe XML configuration file. This has resultant content forgery, cross site scripting, and unvalidated redirection issues.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-85rm-jm8v-379f

больше 3 лет назад

SocuSoft Flash Slideshow Maker Professional through v5.20, when the advanced configuration is used, has an xml_path HTTP parameter that trusts user-supplied input, in conjunction with an unsafe XML configuration file. This has resultant content forgery, cross site scripting, and unvalidated redirection issues.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2017-12439

SocuSoft Flash Slideshow Maker Professional through v5.20, when the advanced configuration is used, has an xml_path HTTP parameter that trusts user-supplied input, in conjunction with an unsafe XML configuration file. This has resultant content forgery, cross site scripting, and unvalidated redirection issues.

CVSS3: 7.5
0%
Низкий
больше 8 лет назад
github логотип
GHSA-85rm-jm8v-379f

SocuSoft Flash Slideshow Maker Professional through v5.20, when the advanced configuration is used, has an xml_path HTTP parameter that trusts user-supplied input, in conjunction with an unsafe XML configuration file. This has resultant content forgery, cross site scripting, and unvalidated redirection issues.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу