Логотип exploitDog
bind:CVE-2017-15714
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2017-15714

Количество 2

Количество 2

nvd логотип

CVE-2017-15714

около 8 лет назад

The BIRT plugin in Apache OFBiz 16.11.01 to 16.11.03 does not escape user input property passed. This allows for code injection by passing that code through the URL. For example by appending this code "__format=%27;alert(%27xss%27)" to the URL an alert window would execute.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-rq9x-7hcg-78pm

больше 3 лет назад

The BIRT plugin in Apache OFBiz 16.11.01 to 16.11.03 does not escape user input property passed. This allows for code injection by passing that code through the URL. For example by appending this code "__format=%27;alert(%27xss%27)" to the URL an alert window would execute.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2017-15714

The BIRT plugin in Apache OFBiz 16.11.01 to 16.11.03 does not escape user input property passed. This allows for code injection by passing that code through the URL. For example by appending this code "__format=%27;alert(%27xss%27)" to the URL an alert window would execute.

CVSS3: 9.8
1%
Низкий
около 8 лет назад
github логотип
GHSA-rq9x-7hcg-78pm

The BIRT plugin in Apache OFBiz 16.11.01 to 16.11.03 does not escape user input property passed. This allows for code injection by passing that code through the URL. For example by appending this code "__format=%27;alert(%27xss%27)" to the URL an alert window would execute.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад

Уязвимостей на страницу