Логотип exploitDog
bind:CVE-2017-9451
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2017-9451

Количество 2

Количество 2

nvd логотип

CVE-2017-9451

больше 8 лет назад

Cross site scripting (XSS) vulnerability in pages.edit_form.php in flatCore 1.4.6 allows remote attackers to inject arbitrary JavaScript via the PATH_INFO in an acp.php URL, due to use of unsanitized $_SERVER['PHP_SELF'] to generate URLs.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-5x93-pjrr-4q9x

больше 3 лет назад

Cross site scripting (XSS) vulnerability in pages.edit_form.php in flatCore 1.4.6 allows remote attackers to inject arbitrary JavaScript via the PATH_INFO in an acp.php URL, due to use of unsanitized $_SERVER['PHP_SELF'] to generate URLs.

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2017-9451

Cross site scripting (XSS) vulnerability in pages.edit_form.php in flatCore 1.4.6 allows remote attackers to inject arbitrary JavaScript via the PATH_INFO in an acp.php URL, due to use of unsanitized $_SERVER['PHP_SELF'] to generate URLs.

CVSS3: 6.1
0%
Низкий
больше 8 лет назад
github логотип
GHSA-5x93-pjrr-4q9x

Cross site scripting (XSS) vulnerability in pages.edit_form.php in flatCore 1.4.6 allows remote attackers to inject arbitrary JavaScript via the PATH_INFO in an acp.php URL, due to use of unsanitized $_SERVER['PHP_SELF'] to generate URLs.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу