Логотип exploitDog
bind:CVE-2018-11039
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2018-11039

Количество 6

Количество 6

ubuntu логотип

CVE-2018-11039

почти 7 лет назад

Spring Framework (versions 5.0.x prior to 5.0.7, versions 4.3.x prior to 4.3.18, and older unsupported versions) allow web applications to change the HTTP request method to any HTTP method (including TRACE) using the HiddenHttpMethodFilter in Spring MVC. If an application has a pre-existing XSS vulnerability, a malicious user (or attacker) can use this filter to escalate to an XST (Cross Site Tracing) attack.

CVSS3: 5.9
EPSS: Низкий
redhat логотип

CVE-2018-11039

около 7 лет назад

Spring Framework (versions 5.0.x prior to 5.0.7, versions 4.3.x prior to 4.3.18, and older unsupported versions) allow web applications to change the HTTP request method to any HTTP method (including TRACE) using the HiddenHttpMethodFilter in Spring MVC. If an application has a pre-existing XSS vulnerability, a malicious user (or attacker) can use this filter to escalate to an XST (Cross Site Tracing) attack.

CVSS3: 3.7
EPSS: Низкий
nvd логотип

CVE-2018-11039

почти 7 лет назад

Spring Framework (versions 5.0.x prior to 5.0.7, versions 4.3.x prior to 4.3.18, and older unsupported versions) allow web applications to change the HTTP request method to any HTTP method (including TRACE) using the HiddenHttpMethodFilter in Spring MVC. If an application has a pre-existing XSS vulnerability, a malicious user (or attacker) can use this filter to escalate to an XST (Cross Site Tracing) attack.

CVSS3: 5.9
EPSS: Низкий
debian логотип

CVE-2018-11039

почти 7 лет назад

Spring Framework (versions 5.0.x prior to 5.0.7, versions 4.3.x prior ...

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-9gcm-f4x3-8jpw

больше 6 лет назад

Spring Framework Cross Site Tracing (XST)

CVSS3: 5.9
EPSS: Низкий
fstec логотип

BDU:2019-00563

почти 7 лет назад

Уязвимость реализации механизма HiddenHttpMethodFilter программной платформы Spring Framework, позволяющая нарушителю осуществить межсайтовую сценарную атаку

CVSS3: 5.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2018-11039

Spring Framework (versions 5.0.x prior to 5.0.7, versions 4.3.x prior to 4.3.18, and older unsupported versions) allow web applications to change the HTTP request method to any HTTP method (including TRACE) using the HiddenHttpMethodFilter in Spring MVC. If an application has a pre-existing XSS vulnerability, a malicious user (or attacker) can use this filter to escalate to an XST (Cross Site Tracing) attack.

CVSS3: 5.9
3%
Низкий
почти 7 лет назад
redhat логотип
CVE-2018-11039

Spring Framework (versions 5.0.x prior to 5.0.7, versions 4.3.x prior to 4.3.18, and older unsupported versions) allow web applications to change the HTTP request method to any HTTP method (including TRACE) using the HiddenHttpMethodFilter in Spring MVC. If an application has a pre-existing XSS vulnerability, a malicious user (or attacker) can use this filter to escalate to an XST (Cross Site Tracing) attack.

CVSS3: 3.7
3%
Низкий
около 7 лет назад
nvd логотип
CVE-2018-11039

Spring Framework (versions 5.0.x prior to 5.0.7, versions 4.3.x prior to 4.3.18, and older unsupported versions) allow web applications to change the HTTP request method to any HTTP method (including TRACE) using the HiddenHttpMethodFilter in Spring MVC. If an application has a pre-existing XSS vulnerability, a malicious user (or attacker) can use this filter to escalate to an XST (Cross Site Tracing) attack.

CVSS3: 5.9
3%
Низкий
почти 7 лет назад
debian логотип
CVE-2018-11039

Spring Framework (versions 5.0.x prior to 5.0.7, versions 4.3.x prior ...

CVSS3: 5.9
3%
Низкий
почти 7 лет назад
github логотип
GHSA-9gcm-f4x3-8jpw

Spring Framework Cross Site Tracing (XST)

CVSS3: 5.9
3%
Низкий
больше 6 лет назад
fstec логотип
BDU:2019-00563

Уязвимость реализации механизма HiddenHttpMethodFilter программной платформы Spring Framework, позволяющая нарушителю осуществить межсайтовую сценарную атаку

CVSS3: 5.9
3%
Низкий
почти 7 лет назад

Уязвимостей на страницу