Логотип exploitDog
bind:CVE-2017-12630
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2017-12630

Количество 2

Количество 2

nvd логотип

CVE-2017-12630

около 8 лет назад

In Apache Drill 1.11.0 and earlier when submitting form from Query page users are able to pass arbitrary script or HTML which will take effect on Profile page afterwards. Example: after submitting special script that returns cookie information from Query page, malicious user may obtain this information from Profile page afterwards.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xp4g-5xj6-6vpr

больше 3 лет назад

Apache Drill vulnerable to Cross-site Scripting

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2017-12630

In Apache Drill 1.11.0 and earlier when submitting form from Query page users are able to pass arbitrary script or HTML which will take effect on Profile page afterwards. Example: after submitting special script that returns cookie information from Query page, malicious user may obtain this information from Profile page afterwards.

CVSS3: 5.4
1%
Низкий
около 8 лет назад
github логотип
GHSA-xp4g-5xj6-6vpr

Apache Drill vulnerable to Cross-site Scripting

CVSS3: 5.4
1%
Низкий
больше 3 лет назад

Уязвимостей на страницу