Логотип exploitDog
bind:CVE-2018-19509
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2018-19509

Количество 2

Количество 2

nvd логотип

CVE-2018-19509

почти 7 лет назад

wg7.php in Webgalamb 7.0 makes opportunistic calls to htmlspecialchars() instead of using a templating engine with proper contextual encoding. Because it is possible to insert arbitrary strings into the database, any JavaScript could be executed by the administrator, leading to XSS.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-7p33-8822-cxph

больше 3 лет назад

wg7.php in Webgalamb 7.0 makes opportunistic calls to htmlspecialchars() instead of using a templating engine with proper contextual encoding. Because it is possible to insert arbitrary strings into the database, any JavaScript could be executed by the administrator, leading to XSS.

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2018-19509

wg7.php in Webgalamb 7.0 makes opportunistic calls to htmlspecialchars() instead of using a templating engine with proper contextual encoding. Because it is possible to insert arbitrary strings into the database, any JavaScript could be executed by the administrator, leading to XSS.

CVSS3: 6.1
0%
Низкий
почти 7 лет назад
github логотип
GHSA-7p33-8822-cxph

wg7.php in Webgalamb 7.0 makes opportunistic calls to htmlspecialchars() instead of using a templating engine with proper contextual encoding. Because it is possible to insert arbitrary strings into the database, any JavaScript could be executed by the administrator, leading to XSS.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу